CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2019-19981

    Last Modified: 21 Nov 2024

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

    Published: 26 Dec 2019
    5.3
    Medium

    CVE-2019-19982

    Last Modified: 21 Nov 2024

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.

    Published: 26 Dec 2019
    4.3
    Medium

    CVE-2019-19983

    Last Modified: 21 Nov 2024

    In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.

    Published: 26 Dec 2019
    6.3
    Medium

    CVE-2019-19984

    Last Modified: 21 Nov 2024

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.

    Published: 26 Dec 2019
    5.3
    Medium

    CVE-2019-19985

    Last Modified: 21 Nov 2024

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

    Published: 26 Dec 2019
    7.1
    High

    CVE-2019-16789

    Last Modified: 21 Nov 2024

    In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would get parsed by Waitress as being a chunked request, but a front-end server would use the Content-Length instead as the Transfer-Encoding header is considered invalid due to containing invalid characters. If a front-end server does HTTP pipelining to a backend Waitress server this could lead to HTTP request splitting which may lead to potential cache poisoning or unexpected information disclosure. This issue is fixed in Waitress 1.4.1 through more strict HTTP field validation.

    Published: 26 Dec 2019
    6.1
    Medium

    CVE-2018-18288

    Last Modified: 21 Nov 2024

    CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.

    Published: 26 Dec 2019
    9.8
    Critical

    CVE-2019-17006

    Last Modified: 21 Nov 2024

    In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

    Published: 26 Dec 2019
    9.8
    Critical

    CVE-2019-19977

    Last Modified: 21 Nov 2024

    libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-19967

    Last Modified: 21 Nov 2024

    The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.

    Published: 25 Dec 2019
    5.3
    Medium

    CVE-2019-19960

    Last Modified: 21 Nov 2024

    In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.

    Published: 24 Dec 2019
    7.5
    High

    CVE-2019-19962

    Last Modified: 21 Nov 2024

    wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

    Published: 24 Dec 2019
    5.3
    Medium

    CVE-2019-19963

    Last Modified: 21 Nov 2024

    An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.

    Published: 24 Dec 2019
    6.5
    Medium

    CVE-2019-19958

    Last Modified: 21 Nov 2024

    In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.

    Published: 24 Dec 2019
    6.5
    Medium

    CVE-2019-19957

    Last Modified: 21 Nov 2024

    In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.

    Published: 24 Dec 2019
    9.9
    Critical

    CVE-2019-10758

    Last Modified: 27 Oct 2025

    mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

    Published: 24 Dec 2019
    7.8
    High

    CVE-2019-5702

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

    Published: 24 Dec 2019
    7.5
    High

    CVE-2019-19925

    Last Modified: 21 Nov 2024

    zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

    Published: 24 Dec 2019
    5.3
    Medium

    CVE-2019-19924

    Last Modified: 21 Nov 2024

    SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.

    Published: 24 Dec 2019
    7.5
    High

    CVE-2019-19923

    Last Modified: 21 Nov 2024

    flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

    Published: 24 Dec 2019
    7.5
    High

    CVE-2019-19956

    Last Modified: 3 Dec 2025

    xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

    Published: 24 Dec 2019
    6.1
    Medium

    CVE-2019-18249

    Last Modified: 21 Nov 2024

    Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on a malicious link.

    Published: 24 Dec 2019
    7.3
    High

    CVE-2019-19954

    Last Modified: 21 Nov 2024

    Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.

    Published: 24 Dec 2019
    4.6
    Medium

    CVE-2017-16778

    Last Modified: 21 Nov 2024

    An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit owner may allow such an access grant. However, due to incorrect access control, an attacker could inject it via the speaker unit to perform an access grant to gain unauthorized access, as demonstrated by a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).

    Published: 24 Dec 2019
    7.5
    High

    CVE-2019-19695

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow an attacker to create a symbolic link to a target file and modify it.

    Published: 24 Dec 2019
    9.8
    Critical

    CVE-2019-19950

    Last Modified: 21 Nov 2024

    In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

    Published: 24 Dec 2019
    9.8
    Critical

    CVE-2019-19951

    Last Modified: 21 Nov 2024

    In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

    Published: 24 Dec 2019
    9.1
    Critical

    CVE-2019-19953

    Last Modified: 21 Nov 2024

    In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

    Published: 24 Dec 2019
    4.7
    Medium

    CVE-2019-19965

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

    Published: 24 Dec 2019
    4.6
    Medium

    CVE-2019-19966

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.

    Published: 24 Dec 2019
    4.6
    Medium

    CVE-2019-19947

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-12568

    Last Modified: 21 Nov 2024

    Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-12567

    Last Modified: 21 Nov 2024

    Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2018-10389

    Last Modified: 21 Nov 2024

    Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2018-10388

    Last Modified: 21 Nov 2024

    Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2018-10387

    Last Modified: 21 Nov 2024

    Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161.

    Published: 23 Dec 2019
    8.8
    High

    CVE-2019-18211

    Last Modified: 21 Nov 2024

    An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbitrary remote code execution for any low-privilege user.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-7489

    Last Modified: 21 Nov 2024

    A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-7488

    Last Modified: 21 Nov 2024

    Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-8293

    Last Modified: 21 Nov 2024

    Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5584

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5565

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5566

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5567

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5568

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5569

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5570

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5571

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5572

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019
    —
    Unknown

    CVE-2019-5573

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 23 Dec 2019