Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2019
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
CVSS Score
9.8
EPSS Score
0.007
Published
2019-07-05
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.
CVSS Score
8.1
EPSS Score
0.005
Published
2019-07-05
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.
CVSS Score
9.8
EPSS Score
0.009
Published
2019-07-05
Invoxia NVX220 devices allow TELNET access as admin with a default password.
CVSS Score
9.8
EPSS Score
0.01
Published
2019-07-05
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-07-05
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
CVSS Score
7.5
EPSS Score
0.009
Published
2019-07-05
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-05
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-05
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.
CVSS Score
5.3
EPSS Score
0.608
Published
2019-07-05
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
CVSS Score
6.1
EPSS Score
0.795
Published
2019-07-05


Contact Us

Shodan ® - All rights reserved