Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-0493 1 Oracle 1 Mysql 2019-12-17 2.1 LOW N/A
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, and CVE-2012-0495.
CVE-2012-0494 1 Oracle 1 Mysql 2019-12-17 1.7 LOW N/A
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.
CVE-2019-15631 1 Mulesoft 2 Api Gateway, Mule Runtime 2019-12-13 7.5 HIGH 9.8 CRITICAL
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
CVE-2019-18251 2 Omron, Teamviewer 2 Cx-supervisor, Teamviewer 2019-12-11 6.8 MEDIUM 8.8 HIGH
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.
CVE-2017-16764 1 Django Make App Project 1 Django Make App 2019-12-11 7.5 HIGH 9.8 CRITICAL
An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.
CVE-2013-7325 1 Debian 2 Debian Linux, Devscripts 2019-12-06 6.5 MEDIUM 8.8 HIGH
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
CVE-2017-0359 2 Debian, Reproducible Builds 2 Debian Linux, Diffoscope 2019-12-03 10.0 HIGH 9.8 CRITICAL
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
CVE-2018-0157 1 Cisco 1 Ios Xe 2019-12-03 7.8 HIGH 8.6 HIGH
A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exploit this vulnerability by sending fragmented IP Version 4 or IP Version 6 packets through an affected device. An exploit could allow the attacker to cause the device to crash, resulting in a denial of service (DoS) condition. The following releases of Cisco IOS XE Software are vulnerable: Everest-16.4.1, Everest-16.4.2, Everest-16.5.1, Everest-16.5.1b, Everest-16.6.1, Everest-16.6.1a. Cisco Bug IDs: CSCvf60296.
CVE-2019-2941 1 Oracle 1 Hyperion Enterprise Performance Management Architect 2019-11-27 3.6 LOW 4.0 MEDIUM
Vulnerability in the Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Modeling). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Profitability and Cost Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperion Profitability and Cost Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Profitability and Cost Management accessible data as well as unauthorized read access to a subset of Hyperion Profitability and Cost Management accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N).
CVE-2019-2315 1 Qualcomm 86 Apq8009, Apq8009 Firmware, Apq8017 and 83 more 2019-11-25 7.2 HIGH 7.8 HIGH
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure environment. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, Snapdragon_High_Med_2016, SXR1130, SXR2130
CVE-2011-5330 1 Distributed Ruby Project 1 Distributed Ruby 2019-11-22 7.5 HIGH 9.8 CRITICAL
Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.
CVE-2011-5331 1 Distributed Ruby Project 1 Distributed Ruby 2019-11-22 7.5 HIGH 9.8 CRITICAL
Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.
CVE-2019-6186 1 Lenovo 1 System Interface Foundation 2019-11-21 6.5 MEDIUM 8.8 HIGH
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
CVE-2019-6176 1 Lenovo 2 Thinkpad Usb-c Dock, Thinkpad Usb-c Dock Firmware 2019-11-21 5.0 MEDIUM 7.5 HIGH
A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
CVE-2019-18981 1 Pimcore 1 Pimcore 2019-11-21 7.5 HIGH 9.8 CRITICAL
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
CVE-2011-4941 1 Matomo 1 Matomo 2019-11-21 6.8 MEDIUM N/A
Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown attack vectors.
CVE-2016-5194 1 Google 1 Chrome 2019-11-21 10.0 HIGH 9.8 CRITICAL
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
CVE-2018-0589 1 Ultimatemember 1 User Profile \& Membership 2019-11-20 4.0 MEDIUM 4.3 MEDIUM
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
CVE-2018-0590 1 Ultimatemember 1 User Profile \& Membership 2019-11-20 4.0 MEDIUM 4.3 MEDIUM
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
CVE-2019-18373 1 Symantec 1 Norton App Lock 2019-11-20 4.4 MEDIUM 5.6 MEDIUM
Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.