Unknown · CVSS Not scored
PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via crafted JavaScript code in the KeySkills field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions set at install time. This allows code to be run as NT AUTHORITY/SYSTEM.
Published Mar 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.
Published Mar 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
Published Mar 12, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
Published Mar 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow remote, unauthenticated attackers to execute arbitrary code or cause a denial of service via malicious L2CAP configuration requests, in conjunction with crafted SDP communication over maliciously configured L2CAP channels. The attacker must have connectivity over the Bluetooth physical layer, and must be able to send raw L2CAP frames. This is related to L2Cap_HandleConfigReq in core/stack/l2cap/l2cap_sm.c and SdpServHandleServiceSearchAttribReq in core/stack/sdp/sdpserv.c.
Published Mar 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a special map file to execute arbitrary code when the map file is loaded.
Published Mar 2, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.
Published Mar 20, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.
Published Mar 20, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
Published Mar 20, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be able to derive information about the high bits of the secret key, as the function to derive the public point from the secret scalar uses an unblinded Montgomery ladder whose loop iteration count depends on the bitlength of the secret. This issue affects only key generation, not ECDSA signatures or ECDH key agreement.
Published Mar 8, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.
Published Mar 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).
Published Mar 15, 2019 · Updated Aug 5, 2024