Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-18371 Path Traversal vulnerability in MI Millet Router 3G Firmware
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable.
network
low complexity
mi CWE-22
7.5
2019-10-23 CVE-2014-2304 Improper Input Validation vulnerability in Projectfloodlight Open SDN Controller 0.90
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the controller service.
network
low complexity
projectfloodlight CWE-20
7.5
2019-10-23 CVE-2002-2439 Integer Overflow or Wraparound vulnerability in GNU GCC
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
local
low complexity
gnu CWE-190
7.8
2019-10-23 CVE-2019-17093 Uncontrolled Search Path Element vulnerability in multiple products
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8.
local
low complexity
avg avast CWE-427
7.8
2019-10-23 CVE-2013-7333 Improper Input Validation vulnerability in Projectfloodlight Open SDN Controller 0.90
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from the SDN controller, causing degradation and eventually denial of network access to all devices connected to the targeted switch.
network
low complexity
projectfloodlight CWE-20
7.5
2019-10-23 CVE-2019-11283 Information Exposure Through Log Files vulnerability in multiple products
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs.
network
low complexity
cloudfoundry pivotal-software CWE-532
8.8
2019-10-23 CVE-2019-18280 Cross-Site Request Forgery (CSRF) vulnerability in Online Grading System Project Online Grading System 1.0
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection.
network
low complexity
online-grading-system-project CWE-352
8.8
2019-10-23 CVE-2019-18278 Unspecified vulnerability in Videolan VLC Media Player 3.0.8
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba.
local
low complexity
videolan
7.8
2019-10-23 CVE-2019-18277 HTTP Request Smuggling vulnerability in Haproxy
A flaw was found in HAProxy before 2.0.6.
network
low complexity
haproxy CWE-444
7.5
2019-10-23 CVE-2019-18220 Cross-Site Request Forgery (CSRF) vulnerability in Sitemagic 4.4.1
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests.
network
low complexity
sitemagic CWE-352
8.8