CVE Severity Distribution (Last 30 Days)
Found 8 CVEs in the last 30 days.
CVE-2019-1068
HIGH
CVSS: 8.8
EPSS: 52.8%
VulnCheck KEV
Weaponized
CISA KEV
CWE-20
T1190
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
Published: 2019-07-15
Mentioned in 2 article(s):
CVE-2019-10686
CRITICAL
CVSS: 10.0
EPSS: 1.6%
CWE-918
T1190
An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.
Published: 2019-04-01
CVE-2019-10684
CRITICAL
CVSS: 9.8
EPSS: 2.4%
GHDB
CWE-94
T1059
Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.
Published: 2019-04-01
CVE-2019-10687
CRITICAL
CVSS: 9.8
EPSS: 2.9%
CWE-89
T1190
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
Published: 2019-08-21
CVE-2019-10682
HIGH
CVSS: 7.5
EPSS: 1.2%
CWE-312
T1552
django-nopassword before 5.0.0 stores cleartext secrets in the database.
Published: 2020-03-18
CVE-2019-10688
MEDIUM
CVSS: 6.8
EPSS: 0.3%
CWE-798
T1078
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.
Published: 2019-04-23
CVE-2019-10689
MEDIUM
CVSS: 6.5
EPSS: 0.7%
CWE-287
T1078
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
Published: 2019-06-24
CVE-2019-10685
MEDIUM
CVSS: 6.1
EPSS: 2.3%
ExploitDB
CWE-79
T1189
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
Published: 2019-05-24