Exploit Database

153,618 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-12315 WRITEUP MEDIUM
Samsung SCX-824 Firmware - Reflected Cross-Site Scripting via Print from File Feature
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.
CVSS 6.1
CVE-2019-12502 WRITEUP HIGH
MOBOTIX S14 MX-V4.2.1.61 - Cross-Site Request Forgery via Admin Account Addition
There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.
CVSS 8.8
CVE-2019-12760 WRITEUP LOW
parso < 0.4.0 - Remote Code Execution via Pickle Deserialization
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.
CVSS 3.3
CVE-2019-12761 WRITEUP HIGH
PyXDG < 0.26 - Code Injection via Menu XML Category Element
A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.
CVSS 7.5
CVE-2019-12881 WRITEUP HIGH
Linux Kernel 4.15.0 - Denial of Service via i915_gem_userptr_get_pages NULL Pointer Dereference
i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl calls to /dev/dri/card0.
CVSS 7.8
CVE-2019-13050 WRITEUP HIGH
GnuPG < 2.2.16 - Denial of Service via SKS Keyserver Certificate Spamming
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
CVSS 7.5
CVE-2019-13337 WRITEUP HIGH
WESEEK GROWI < 3.5.0 - Unauthenticated Authorization Bypass via access_token URL Parameter
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required.
CVSS 7.5
CVE-2019-13338 WRITEUP HIGH
WESEEK GROWI < 3.5.0 - Unauthenticated Password Hash Exposure via Page Metadata API
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.
CVSS 7.5
CVE-2019-13405 WRITEUP CRITICAL
Advan VD-1 Firmware 230 - Unauthenticated ADB Service Enablement via AdbSetting.cgi
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any authentication then take the compromised device as a relay or to install mining software.
CVSS 9.8
CVE-2019-13406 WRITEUP HIGH
Advan VD-1 Firmware < 230 - Unauthenticated Arbitrary APK Installation via ApkUpload.cgi
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
CVSS 7.5
CVE-2019-13407 WRITEUP MEDIUM
androvideo vd_1_firmware < 230 - Reflected Cross-Site Scripting via Error Message
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.
CVSS 6.1
CVE-2019-13408 WRITEUP HIGH
Advan VD-1 Firmware < 230 - Unauthenticated Path Traversal via ExportSettings.cgi Download Parameter
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
CVSS 7.5
CVE-2019-13495 WRITEUP MEDIUM
Zyxel XGS2210-52HP Firmware 4.50 - Authenticated Stored Cross-Site Scripting via rpSys.html Name or Location Field
In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.
CVSS 5.4
CVE-2019-13567 WRITEUP HIGH
Zoom < 4.4.53932.0709 - Remote Code Execution via Malicious Launch URL
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.
CVSS 8.8
CVE-2019-13957 WRITEUP CRITICAL
Umbraco 7.3.8 - SQL Injection via nodeName Parameter
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
CVSS 9.8
CVE-2019-14365 WRITEUP HIGH
Intercom plugin <1.2.1 - Info Disclosure
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVSS 7.5
CVE-2019-14366 WRITEUP HIGH
WP SlackSync <1.8.5 - Info Disclosure
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVSS 7.5
CVE-2019-14755 WRITEUP HIGH
Leaf Admin 61.9.0212.10 - Unrestricted Upload of File with Dangerous Type via Profile Photo Feature
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
CVSS 8.8
CVE-2019-14765 WRITEUP HIGH
DIMO YellowBox CRM <6.3.4 - Privilege Escalation
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.
CVSS 8.8
CVE-2019-14766 WRITEUP MEDIUM
DIMO YellowBox CRM < 6.3.4 - Authenticated Path Traversal in File Browser
Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the server filesystem.
CVSS 6.5
CVE-2019-14767 WRITEUP HIGH
DIMO YellowBox CRM < 6.3.4 - Unauthenticated Path Traversal via images/Apparence and servletrecuperefichier
In DIMO YellowBox CRM before 6.3.4, Path Traversal in images/Apparence (dossier=../) and servletrecuperefichier (document=../) allows an unauthenticated user to download arbitrary files from the server.
CVSS 7.5
CVE-2019-14768 WRITEUP HIGH
DIMO YellowBox CRM < 6.3.4 - Arbitrary File Upload & RCE via Path Traversal
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.
CVSS 8.8
CVE-2019-14932 WRITEUP HIGH
Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 - Authorization Bypass via selApp Parameter
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resumeDetail.cfm. This includes personal information and other sensitive data.
CVSS 7.5
CVE-2019-14937 WRITEUP HIGH
REDCap 8.11.5-9.2.9 - Time-Based SQL Injection via Calendar Event cal_id Parameter
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
CVSS 7.5
CVE-2019-15059 WRITEUP HIGH
Liberty lisPBX 2.0-4 - Unauthenticated Sensitive Information Exposure via Backup File Retrieval
In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-DD.tar without authentication or authorization. These configuration files have all PBX information including extension numbers, contacts, and passwords.
CVSS 7.5