CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.2

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging /…

Published: Aug 01, 2019
Modified: Oct 27, 2025
Product: debian debian_linux
EPSS: 93.20%
View Details
10.0

CVE-2019-11708

Critical KEV

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects…

Published: Jul 23, 2019
Modified: Oct 27, 2025
Product: mozilla firefox
EPSS: 68.89%
View Details
8.1

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

Published: Jul 19, 2019
Modified: Nov 04, 2025
EPSS: 93.03%
View Details
8.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

Published: Jul 16, 2019
Modified: Nov 06, 2025
Product: citrix netscaler_sd-wan
EPSS: 80.99%
View Details
9.8

CVE-2019-12989

Critical KEV

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

Published: Jul 16, 2019
Modified: Nov 06, 2025
Product: citrix netscaler_sd-wan
EPSS: 91.05%
View Details
7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

Published: Jul 15, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 1.93%
View Details
7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

Published: Jul 15, 2019
Modified: Oct 29, 2025
Product: microsoft windows_server_1803
EPSS: 3.11%
View Details
7.8

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

Published: Jul 15, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 4.00%
View Details
7.5

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

Published: Jul 03, 2019
Modified: Nov 07, 2025
EPSS: 91.08%
View Details
7.5

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Published: Jul 03, 2019
Modified: Nov 07, 2025
EPSS: 91.14%
View Details
7.8

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update…

Published: Jun 12, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 30.46%
View Details
7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have…

Published: Jun 12, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 11.34%
View Details
9.8

CVE-2010-5330

Critical KEV

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example,…

Published: Jun 11, 2019
Modified: Nov 05, 2025
EPSS: 56.48%
View Details
9.8

CVE-2019-11580

Critical KEV

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable…

Published: Jun 03, 2019
Modified: Oct 24, 2025
EPSS: 94.39%
View Details
8.8

Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.

Published: May 31, 2019
Modified: Nov 07, 2025
EPSS: 24.77%
View Details
9.8

CVE-2019-9874

Critical KEV

Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Published: May 31, 2019
Modified: Nov 07, 2025
EPSS: 75.40%
View Details
9.8

CVE-2019-9670

Critical KEV

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

Published: May 29, 2019
Modified: Nov 04, 2025
Product: synacor zimbra_collaboration_suite
EPSS: 94.43%
View Details
4.3

CVE-2018-13383

Medium KEV

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle…

Published: May 29, 2019
Modified: Oct 24, 2025
Product: fortinet fortios
EPSS: 1.32%
View Details
9.8

CVE-2019-11634

Critical KEV

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Published: May 22, 2019
Modified: Nov 06, 2025
Product: citrix receiver
EPSS: 52.84%
View Details
8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

Published: May 16, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 34.44%
View Details
9.8

CVE-2018-14839

Critical KEV

LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.

Published: May 14, 2019
Modified: Nov 07, 2025
Product: lg n1a1_firmware
EPSS: 90.30%
View Details
9.8

CVE-2019-3568

Critical KEV

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for…

Published: May 14, 2019
Modified: Oct 24, 2025
Product: whatsapp whatsapp_business
EPSS: 45.98%
View Details
8.8

An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Published: May 06, 2019
Modified: Dec 15, 2025
EPSS: 0.93%
View Details
9.8

CVE-2017-18368

Critical KEV

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

Published: May 02, 2019
Modified: Nov 05, 2025
Product: billion 5200w-t_firmware
EPSS: 93.75%
View Details