Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2019-17558
Known exploited
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).
CVSS Score
7.5
EPSS Score
0.986
Published
2019-12-30
CVE-2019-17621
Known exploited
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
CVSS Score
9.8
EPSS Score
0.896
Published
2019-12-30
CVE-2019-20085
Known exploited
TVT NVMS-1000 devices allow GET /.. Directory Traversal
CVSS Score
7.5
EPSS Score
0.961
Published
2019-12-30
CVE-2019-19781
Known exploited
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVSS Score
9.8
EPSS Score
1.0
Published
2019-12-27
CVE-2019-10758
Known exploited
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
CVSS Score
9.9
EPSS Score
0.848
Published
2019-12-24
CVE-2019-7483
Known exploited
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CVSS Score
7.5
EPSS Score
0.04
Published
2019-12-19
CVE-2019-8605
Known exploited
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
CVSS Score
7.8
EPSS Score
0.175
Published
2019-12-18
CVE-2019-8526
Known exploited
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.007
Published
2019-12-18
CVE-2019-7286
Known exploited
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.156
Published
2019-12-18
CVE-2019-7287
Known exploited
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
CVSS Score
7.8
EPSS Score
0.046
Published
2019-12-18


Contact Us

Shodan ® - All rights reserved