Vulnerabilities
14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-1493 | A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been rated as problematic. This issue affects the function 0x220019 in the library MaxProctetor64.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223379. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2020-12122 | In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecifie In Max Secure Max Spyware Detector 1.0.0.044, the driver file (MaxProc64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2200019. (This also extends to the various other products from Max Secure that include MaxProc64.sys.) NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2020-6956 | PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp. PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-19382 | Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation. NVD description · AI analysis pending | 7.8 | <1% | PoC ×2 |
| — | |
| CVE-2019-11196 | An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to g An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings). NVD description · AI analysis pending | 9.8 | 6% | PoC |
| — | |
| CVE-2018-6209 | In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified othe In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — |