Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2019-20085
Known exploited
TVT NVMS-1000 devices allow GET /.. Directory Traversal
CVSS Score
7.5
EPSS Score
0.961
Published
2019-12-30
CVE-2019-19781
Known exploited
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVSS Score
9.8
EPSS Score
1.0
Published
2019-12-27
CVE-2019-10758
Known exploited
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
CVSS Score
9.9
EPSS Score
0.847
Published
2019-12-24
CVE-2019-7483
Known exploited
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CVSS Score
7.5
EPSS Score
0.04
Published
2019-12-19
CVE-2019-8605
Known exploited
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
CVSS Score
7.8
EPSS Score
0.175
Published
2019-12-18
CVE-2019-8526
Known exploited
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.007
Published
2019-12-18
CVE-2019-7286
Known exploited
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.
CVSS Score
7.8
EPSS Score
0.156
Published
2019-12-18
CVE-2019-7287
Known exploited
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges.
CVSS Score
7.8
EPSS Score
0.046
Published
2019-12-18
CVE-2019-8506
Known exploited
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
CVSS Score
8.8
EPSS Score
0.181
Published
2019-12-18
CVE-2019-4716
Known exploited
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
CVSS Score
10.0
EPSS Score
0.864
Published
2019-12-18


Contact Us

Shodan ® - All rights reserved