CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

Published: Apr 09, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 9.88%
View Details
7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

Published: Apr 09, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 6.09%
View Details
6.5

CVE-2019-0703

Medium KEV

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

Published: Apr 09, 2019
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 19.23%
View Details
7.2

On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field.

Published: Apr 08, 2019
Modified: Nov 06, 2025
Product: reolink c1_pro_firmware
EPSS: 50.61%
View Details
7.8

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

Published: Apr 03, 2019
Modified: Oct 23, 2025
Product: apple mac_os_x
EPSS: 0.19%
View Details
9.8

CVE-2019-10068

Critical KEV

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object…

Published: Mar 26, 2019
Modified: Dec 19, 2025
EPSS: 93.89%
View Details
10.0

CVE-2019-7609

Critical KEV

Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana…

Published: Mar 25, 2019
Modified: Nov 07, 2025
Product: redhat openshift_container_platform
EPSS: 94.45%
View Details
9.8

CVE-2019-7238

Critical KEV

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Published: Mar 21, 2019
Modified: Nov 06, 2025
EPSS: 94.38%
View Details
9.9

CVE-2019-1003029

Critical KEV

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

Published: Mar 08, 2019
Modified: Oct 24, 2025
Product: redhat openshift_container_platform
EPSS: 92.78%
View Details
6.5

CVE-2018-18809

Medium KEV

The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS…

Published: Mar 07, 2019
Modified: Nov 07, 2025
Product: tibco jasperreports_library
EPSS: 94.01%
View Details
6.5

CVE-2019-0676

Medium KEV

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

Published: Mar 05, 2019
Modified: Oct 29, 2025
Product: microsoft internet_explorer
EPSS: 24.49%
View Details
7.5

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

Published: Mar 05, 2019
Modified: Oct 23, 2025
Product: apple iphone_os
EPSS: 0.17%
View Details
9.8

CVE-2018-20753

Critical KEV

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Published: Feb 05, 2019
Modified: Nov 07, 2025
EPSS: 44.44%
View Details
9.8

CVE-2017-18362

Critical KEV

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If…

Published: Feb 05, 2019
Modified: Nov 05, 2025
EPSS: 87.16%
View Details
9.8

CVE-2018-19323

Critical KEV

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

Published: Dec 21, 2018
Modified: Nov 07, 2025
Product: gigabyte xtreme_gaming_engine
EPSS: 9.21%
View Details
7.8

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with…

Published: Dec 21, 2018
Modified: Nov 07, 2025
Product: gigabyte xtreme_gaming_engine
EPSS: 2.88%
View Details
7.8

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

Published: Dec 21, 2018
Modified: Nov 07, 2025
Product: gigabyte xtreme_gaming_engine
EPSS: 39.81%
View Details
7.8

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

Published: Dec 21, 2018
Modified: Nov 07, 2025
Product: gigabyte xtreme_gaming_engine
EPSS: 38.68%
View Details
7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.

Published: Dec 20, 2018
Modified: Oct 29, 2025
Product: microsoft internet_explorer
EPSS: 22.99%
View Details
7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016,…

Published: Dec 12, 2018
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 34.33%
View Details
7.8

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows…

Published: Dec 12, 2018
Modified: Oct 29, 2025
Product: microsoft windows_10_1607
EPSS: 16.36%
View Details
9.8

CVE-2018-20062

Critical KEV

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

Published: Dec 11, 2018
Modified: Nov 07, 2025
Product: 5none nonecms
EPSS: 94.31%
View Details
8.8

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Published: Dec 11, 2018
Modified: Oct 24, 2025
Product: redhat enterprise_linux_server
EPSS: 31.92%
View Details
9.8

CVE-2018-1000861

Critical KEV

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

Published: Dec 10, 2018
Modified: Nov 05, 2025
Product: jenkins jenkins
EPSS: 94.49%
View Details