Exploit Database

153,618 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-17501 WRITEUP HIGH
Centreon 19.04 - OS Command Injection via Command Line Field
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and may be the same.
CVSS 8.8
CVE-2019-17502 WRITEUP HIGH
hydra_project/hydra < 0.1.8 - Denial of Service via NULL Pointer Dereference in POST Request Handling
Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Length header. read.c, request.c, and util.c contribute to this. The process_header_end() function calls boa_atoi(), which ultimately calls atoi() on a NULL pointer.
CVSS 7.5
CVE-2019-17527 WRITEUP CRITICAL
JS JOBS FREE < 1.2.7 - SQL Injection via Custom Fields Child Parameter
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.
CVSS 9.8
CVE-2019-17604 WRITEUP MEDIUM
eyecomms eyeCMS < 2019-10-15 - Insecure Direct Object Reference via Candidate ID Parameter
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV, phone number, and all other personal information) by changing the value of the candidate id (the id parameter).
CVSS 4.3
CVE-2019-17605 WRITEUP HIGH
eyecomms eyeCMS < 2019-10-15 - Authorization Bypass via Mass Assignment
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.
CVSS 8.8
CVE-2019-18210 WRITEUP MEDIUM
Moodle < 3.7.2 - Authenticated Stored Cross-Site Scripting via introeditor[text] Parameter
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_role page). Because the vendor has this expectation, they have stated "this report has been closed as a false positive, and not a bug."
CVSS 5.4
CVE-2019-18411 WRITEUP HIGH
ManageEngine ADSelfService Plus 5.x-5803 - Cross-Site Request Forgery on Profile Information Page
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.
CVSS 8.8
CVE-2019-18646 WRITEUP HIGH
Untangle NG <14.2.0 - Authenticated SQL Injection
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
CVSS 7.2
CVE-2019-18647 WRITEUP HIGH
Untangle NG <14.2.0 - Command Injection
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
CVSS 7.2
CVE-2019-18648 WRITEUP MEDIUM
Untangle NG Firewall 14.2.0 - Authenticated Reflected Cross-Site Scripting
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
CVSS 4.8
CVE-2019-18649 WRITEUP MEDIUM
Untangle NG Firewall 14.2.0 - Authenticated Stored Cross-Site Scripting in Reports Title Field
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
CVSS 4.8
CVE-2019-18684 WRITEUP HIGH
Sudo <1.8.29 - Privilege Escalation
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and openat system calls. The attacker can write "ALL ALL=(ALL) NOPASSWD:ALL" to /proc/#####/fd/3 at a time when Sudo is prompting for a password. NOTE: This has been disputed due to the way Linux /proc works. It has been argued that writing to /proc/#####/fd/3 would only be viable if you had permission to write to /etc/sudoers. Even with write permission to /proc/#####/fd/3, it would not help you write to /etc/sudoers
CVSS 7.0
CVE-2019-18952 WRITEUP CRITICAL
SibSoft Xfilesharing <2.5.1 - Code Injection
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
CVSS 9.8
CVE-2019-19364 WRITEUP HIGH
Sony Catalyst Production Suite and Catalyst Browse Suite <1.1.0.21 - DLL Hijacking Privilege Escalation
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.
CVSS 7.8
CVE-2019-19389 WRITEUP MEDIUM
Ktor < 1.2.6 - HTTP Response Splitting
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVSS 5.4
CVE-2019-19514 WRITEUP MEDIUM
Ayision Ays-WR01 v28K.RPT.20161224 - XSS
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVSS 5.4
CVE-2019-19515 WRITEUP MEDIUM
Ayision Ays-WR01 v28K.RPT.20161224 - XSS
Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVSS 6.1
CVE-2019-19517 WRITEUP HIGH
Intelbras RF1200 1.1.3 - Cross-Site Request Forgery
Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
CVSS 8.8
CVE-2019-20348 WRITEUP MEDIUM
OKER G232V1 v1.03.02.20161129 - Unauthenticated OS Command Injection via UART Serial Interface
OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to interrupt the boot sequence in order to execute arbitrary commands with root privileges and conduct further attacks.
CVSS 6.8
CVE-2019-6242 WRITEUP HIGH
Kentico Xperience - Insufficiently Protected Credentials in SMTP Configuration
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix it at a future time
CVSS 7.2
CVE-2019-7535 WRITEUP MEDIUM
Gurock TestRail <5.3.0.3603 - Info Disclosure
index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology.
CVSS 5.3
CVE-2019-7673 WRITEUP HIGH
MOBOTIX S14 <MX-V4.2.1.61 - Info Disclosure
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DES hash format.
CVSS 7.5
CVE-2019-7674 WRITEUP CRITICAL
MOBOTIX S14 MX-V4.2.1.61 - Info Disclosure
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
CVSS 9.8
CVE-2019-7675 WRITEUP HIGH
MOBOTIX S14 <MX-V4.2.1.61 - Info Disclosure
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.
CVSS 7.5
CVE-2019-8423 WRITEUP CRITICAL
ZoneMinder < 1.32.3 - SQL Injection via Events Filter Parameter
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
CVSS 9.8