Export limit exceeded: 40393 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40393 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-9742 | 1 Gdata-software | 1 Total Security | 2024-11-21 | N/A |
| gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore files and directories "inside" the \\.\gdwfpcd device are not properly protected, leading to unintended impersonation or object creation. | ||||
| CVE-2019-9713 | 1 Joomla | 1 Joomla\! | 2024-11-21 | N/A |
| An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access. | ||||
| CVE-2019-9693 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | N/A |
| In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id). | ||||
| CVE-2019-9626 | 1 Phpshe | 1 Phpshe | 2024-11-21 | N/A |
| PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. | ||||
| CVE-2019-9615 | 1 Ofcms Project | 1 Ofcms | 2024-11-21 | N/A |
| An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. | ||||
| CVE-2019-9594 | 1 Bluecms Project | 1 Bluecms | 2024-11-21 | N/A |
| BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | ||||
| CVE-2019-9574 | 1 Mishubd | 1 Wp Human Resource Management | 2024-11-21 | N/A |
| The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role. | ||||
| CVE-2019-9568 | 1 Incsub | 1 Forminator | 2024-11-21 | 6.5 Medium |
| The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission. | ||||
| CVE-2019-9566 | 1 Flarumchina | 1 Flarumchina | 2024-11-21 | N/A |
| FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request. | ||||
| CVE-2019-9547 | 1 Spdk | 1 Storage Performance Development Kit | 2024-11-21 | N/A |
| In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains. | ||||
| CVE-2019-9545 | 1 Freedesktop | 1 Poppler | 2024-11-21 | N/A |
| An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero. | ||||
| CVE-2019-9543 | 1 Freedesktop | 1 Poppler | 2024-11-21 | N/A |
| An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit. | ||||
| CVE-2019-9482 | 1 Misp-project | 1 Misp | 2024-11-21 | N/A |
| In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only). | ||||
| CVE-2019-9380 | 1 Google | 1 Android | 2024-11-21 | 6.5 Medium |
| In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123700098 | ||||
| CVE-2019-9377 | 1 Google | 1 Android | 2024-11-21 | 3.3 Low |
| In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599663 | ||||
| CVE-2019-9376 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In Account of Account.java, there is a possible boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android; Versions: Android-9, Android-8.0, Android-8.1; Android ID: A-129287265. | ||||
| CVE-2019-9364 | 1 Google | 1 Android | 2024-11-21 | 3.3 Low |
| In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-73364631 | ||||
| CVE-2019-9351 | 1 Google | 1 Android | 2024-11-21 | 3.3 Low |
| In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to local limited information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599864 | ||||
| CVE-2019-9323 | 1 Google | 1 Android | 2024-11-21 | 5.3 Medium |
| In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-30770233 | ||||
| CVE-2019-9295 | 1 Google | 1 Android | 2024-11-21 | 7.8 High |
| In com.android.apps.tag, there is a possible bypass of user interaction requirements due to a missing permission check. This could lead to a to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-36885811 | ||||