CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2013-4318

    Last Modified: 21 Nov 2024

    File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2015-5290

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.

    Published: 26 Dec 2019
    5.4
    Medium

    CVE-2019-19389

    Last Modified: 21 Nov 2024

    JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2012-3462

    Last Modified: 21 Nov 2024

    A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-5273

    Last Modified: 21 Nov 2024

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attacker may exploit the vulnerability by a malicious certificate, resulting a denial of service on the affected products.

    Published: 26 Dec 2019
    5.5
    Medium

    CVE-2011-1474

    Last Modified: 21 Nov 2024

    A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79.patch, 2.6.38-test3.patch, and 2.6.37.4-test14.patch. A bad bounds check in arch_get_unmapped_area_topdown triggered by programs doing an mmap after a MAP_GROWSDOWN mmap will create an infinite loop condition without releasing the VM semaphore eventually leading to a system crash.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-5274

    Last Modified: 21 Nov 2024

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in an infinite loop, an attacker may exploit the vulnerability via a malicious certificate to perform a denial of service attack on the affected products.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-5275

    Last Modified: 21 Nov 2024

    USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a heap buffer overflow when decoding a certificate, an attacker may exploit the vulnerability by a malicious certificate to perform a denial of service attack on the affected products.

    Published: 26 Dec 2019
    4.9
    Medium

    CVE-2019-5272

    Last Modified: 21 Nov 2024

    USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.

    Published: 26 Dec 2019
    9.8
    Critical

    CVE-2019-19398

    Last Modified: 21 Nov 2024

    M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may lead to malicious code execution.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-19996

    Last Modified: 21 Nov 2024

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-19995

    Last Modified: 21 Nov 2024

    A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.

    Published: 26 Dec 2019
    9.8
    Critical

    CVE-2019-16327

    Last Modified: 21 Nov 2024

    D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-16326

    Last Modified: 21 Nov 2024

    D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.

    Published: 26 Dec 2019
    5.8
    Medium

    CVE-2019-16781

    Last Modified: 21 Nov 2024

    In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.

    Published: 26 Dec 2019
    5.8
    Medium

    CVE-2019-16780

    Last Modified: 21 Nov 2024

    WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.

    Published: 26 Dec 2019
    5.3
    Medium

    CVE-2018-20492

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-19681

    Last Modified: 21 Nov 2024

    Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state that to be able to create alert commands, you need to have admin rights. They also state that the extended ACL system can disable access to specific sections of the configuration, such as defining new alert commands

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6016

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2019
    4.3
    Medium

    CVE-2019-6023

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6025

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type Advanced 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type Advanced 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Premium 1.24 and earlier (Movable Type Premium), and Movable Type Premium (Advanced Edition) 1.24 and earlier (Movable Type Premium) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6031

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via RSS reader.

    Published: 26 Dec 2019
    6.5
    Medium

    CVE-2019-6022

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-6030

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6011

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2019
    7.2
    High

    CVE-2019-6012

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Dec 2019
    6.6
    Medium

    CVE-2019-6013

    Last Modified: 21 Nov 2024

    DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-6014

    Last Modified: 21 Nov 2024

    DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

    Published: 26 Dec 2019
    5.3
    Medium

    CVE-2019-6017

    Last Modified: 21 Nov 2024

    REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_type] via unspecified vectors.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6018

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2019
    7.8
    High

    CVE-2019-6019

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6020

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6021

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

    Published: 26 Dec 2019
    6.5
    Medium

    CVE-2019-6024

    Last Modified: 21 Nov 2024

    Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.

    Published: 26 Dec 2019
    7.8
    High

    CVE-2019-6026

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client program (MR)LanScope Cat detection agent (DA) prior to Ver.9.2.1.0, LanScope Cat server monitoring agent (SA, SAE) prior to Ver.9.2.2.0, LanScope An prior to Ver 2.7.7.0 (LanScope An 2 series), and LanScope An prior to Ver 3.0.8.1 (LanScope An 3 series)) allow authenticated attackers to obtain unauthorized privileges and execute arbitrary code.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-6027

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6029

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2019
    7.4
    High

    CVE-2019-6032

    Last Modified: 21 Nov 2024

    The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6033

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6034

    Last Modified: 21 Nov 2024

    a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-6035

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.

    Published: 26 Dec 2019
    7.8
    High

    CVE-2019-6008

    Last Modified: 21 Nov 2024

    An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and InsightSuiteAE (R1.01.00 ? R1.06.00)) allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2019-19540

    Last Modified: 21 Nov 2024

    The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.

    Published: 26 Dec 2019
    5.4
    Medium

    CVE-2019-19541

    Last Modified: 21 Nov 2024

    The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.

    Published: 26 Dec 2019
    5.4
    Medium

    CVE-2019-19542

    Last Modified: 21 Nov 2024

    The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.

    Published: 26 Dec 2019
    5.9
    Medium

    CVE-2019-20000

    Last Modified: 21 Nov 2024

    The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.

    Published: 26 Dec 2019
    7.2
    High

    CVE-2019-19999

    Last Modified: 21 Nov 2024

    Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-19998

    Last Modified: 21 Nov 2024

    Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.

    Published: 26 Dec 2019
    8.8
    High

    CVE-2019-19979

    Last Modified: 21 Nov 2024

    A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.

    Published: 26 Dec 2019
    4.3
    Medium

    CVE-2019-19980

    Last Modified: 21 Nov 2024

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.

    Published: 26 Dec 2019