Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2019-1129
Known exploited
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
CVSS Score
7.8
EPSS Score
0.018
Published
2019-07-15
CVE-2019-1068
Known exploited
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
CVSS Score
8.8
EPSS Score
0.528
Published
2019-07-15
CVE-2019-0880
Known exploited
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.023
Published
2019-07-15
CVE-2018-15811
Known exploited
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
CVSS Score
7.5
EPSS Score
0.74
Published
2019-07-03
CVE-2018-18325
Known exploited
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
CVSS Score
7.5
EPSS Score
0.74
Published
2019-07-03
CVE-2019-7256
Known exploited
Linear eMerge E3-Series devices allow Command Injections.
CVSS Score
9.8
EPSS Score
0.971
Published
2019-07-02
CVE-2019-5786
Known exploited
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVSS Score
6.5
EPSS Score
0.615
Published
2019-06-27
CVE-2019-1064
Known exploited
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Deployment Service handles hard links.
CVSS Score
7.8
EPSS Score
0.069
Published
2019-06-12
CVE-2019-1069
Known exploited
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
CVSS Score
7.8
EPSS Score
0.061
Published
2019-06-12
CVE-2010-5330
Known exploited
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.
CVSS Score
9.8
EPSS Score
0.338
Published
2019-06-11


Contact Us

Shodan ® - All rights reserved