33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-38793
Best Restaurant Menu by PriceListo Database
8.5
HIGH
EPSS
46.8%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.

CVE-2024-30491
ProfileGrid Database
8.5
HIGH
EPSS
55.2%
2024 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVE-2024-12786
Adobe Downloader General
8.5
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVE-2019-25343
NextVPN Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-732 1 PoC

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.

CVE-2019-25302
Launch Manager General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup.

CVE-2019-25267
Wing FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2019-25286
_GCafé General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25305
JumpStart Web
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.

CVE-2019-3632
McAfee Enterprise Security Manager (ESM) General
8.5
HIGH
EPSS
1.7%
2019 1 PoC

Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input.

CVE-2019-25285
device Controller General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.

CVE-2019-25345
RTK IIS Codec Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.

CVE-2019-25274
ProShow Producer General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2019-25273
IP General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and escalate privileges.

CVE-2019-25309
Zilab Remote Console Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.

CVE-2019-25306
BlackMoon FTP Server General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2019-25612
Admin-Express General
8.5
HIGH
EPSS
0.0%
2019 CWE-787 1 PoC

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges.

CVE-2019-25283
Shrew Soft VPN Client Networking
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.

CVE-2019-25288
Wacom WTabletService General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.

CVE-2019-25231
devolo dLAN Cockpit General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows local non-privileged users to potentially execute arbitrary code. Attackers can exploit the insecure service path configuration by inserting malicious code in the system root path to execute with elevated privileges during application startup or system reboot.

CVE-2019-25266
Wondershare Application Framework Service General
8.5
HIGH
EPSS
0.0%
2019 CWE-428 1 PoC

Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the service's execution context.