CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2012-2092

    Last Modified: 21 Nov 2024

    A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.

    Published: 6 Dec 2019
    3.3
    Low

    CVE-2019-19620

    Last Modified: 21 Nov 2024

    In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file.

    Published: 6 Dec 2019
    7.8
    High

    CVE-2012-1615

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

    Published: 6 Dec 2019
    5.3
    Medium

    CVE-2019-19625

    Last Modified: 21 Nov 2024

    SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2) leaks node information due to a leaky default configuration as indicated in the policy/defaults/dds/governance.xml document.

    Published: 6 Dec 2019
    5.3
    Medium

    CVE-2019-19627

    Last Modified: 21 Nov 2024

    SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2.)

    Published: 6 Dec 2019
    5.9
    Medium

    CVE-2019-11554

    Last Modified: 21 Nov 2024

    The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.

    Published: 6 Dec 2019
    4.8
    Medium

    CVE-2019-19551

    Last Modified: 21 Nov 2024

    In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not being properly sanitized. If this is done and a user (such as an admin) visits the User Management screen and views that user's profile, the XSS payload will render and execute in the context of the victim user's account.

    Published: 6 Dec 2019
    4.8
    Medium

    CVE-2019-19552

    Last Modified: 21 Nov 2024

    In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a user and embed malicious XSS code. When another user (such as an admin) visits the main User Management screen, the XSS payload will render and execute in the context of the victim user's account.

    Published: 6 Dec 2019
    6.1
    Medium

    CVE-2019-19619

    Last Modified: 21 Nov 2024

    domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.

    Published: 6 Dec 2019
    9.8
    Critical

    CVE-2019-19617

    Last Modified: 21 Nov 2024

    phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

    Published: 6 Dec 2019
    4.3
    Medium

    CVE-2019-19616

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the /Home/GetAttachment function.

    Published: 6 Dec 2019
    9.8
    Critical

    CVE-2019-5544

    Last Modified: 30 Oct 2025

    OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

    Published: 6 Dec 2019
    5.3
    Medium

    CVE-2019-1551

    Last Modified: 21 Nov 2024

    There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

    Published: 6 Dec 2019
    5.5
    Medium

    CVE-2019-19746

    Last Modified: 21 Nov 2024

    make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.

    Published: 6 Dec 2019
    7.5
    High

    CVE-2019-19343

    Last Modified: 21 Nov 2024

    A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

    Published: 6 Dec 2019
    6.1
    Medium

    CVE-2012-1115

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.

    Published: 5 Dec 2019
    6.1
    Medium

    CVE-2012-1114

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.

    Published: 5 Dec 2019
    3.5
    Low

    CVE-2019-16768

    Last Modified: 21 Nov 2024

    In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may leak and be visible to the customer. A validation message with the exception details will be presented to the user when one will try to log into the shop. This has been patched in versions 1.3.14, 1.4.10, 1.5.7, and 1.6.3.

    Published: 5 Dec 2019
    7.2
    High

    CVE-2019-19609

    Last Modified: 21 Nov 2024

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.

    Published: 5 Dec 2019
    4.2
    Medium

    CVE-2019-16769

    Last Modified: 21 Nov 2024

    The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.

    Published: 5 Dec 2019
    5.5
    Medium

    CVE-2012-1105

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.

    Published: 5 Dec 2019
    5.3
    Medium

    CVE-2012-1104

    Last Modified: 21 Nov 2024

    A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.

    Published: 5 Dec 2019
    8.6
    High

    CVE-2019-5098

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can cause out-of-bounds memory read. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

    Published: 5 Dec 2019
    6.5
    Medium

    CVE-2019-19546

    Last Modified: 21 Nov 2024

    Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.

    Published: 5 Dec 2019
    6.3
    Medium

    CVE-2019-19545

    Last Modified: 21 Nov 2024

    Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.

    Published: 5 Dec 2019
    6.3
    Medium

    CVE-2019-18381

    Last Modified: 21 Nov 2024

    Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.

    Published: 5 Dec 2019
    7.8
    High

    CVE-2019-17388

    Last Modified: 21 Nov 2024

    Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.

    Published: 5 Dec 2019
    7.8
    High

    CVE-2019-17387

    Last Modified: 21 Nov 2024

    An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.

    Published: 5 Dec 2019
    4.8
    Medium

    CVE-2019-7185

    Last Modified: 21 Nov 2024

    This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.

    Published: 5 Dec 2019
    4.8
    Medium

    CVE-2019-7184

    Last Modified: 21 Nov 2024

    This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-7183

    Last Modified: 21 Nov 2024

    This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-7195

    Last Modified: 27 Oct 2025

    This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-7194

    Last Modified: 27 Oct 2025

    This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-7193

    Last Modified: 27 Oct 2025

    This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-7192

    Last Modified: 27 Oct 2025

    This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

    Published: 5 Dec 2019
    6.1
    Medium

    CVE-2019-19466

    Last Modified: 21 Nov 2024

    SCEditor 2.1.3 allows XSS.

    Published: 5 Dec 2019
    9.6
    Critical

    CVE-2019-15897

    Last Modified: 21 Nov 2024

    beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).

    Published: 5 Dec 2019
    6.8
    Medium

    CVE-2019-3690

    Last Modified: 21 Nov 2024

    The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed by chkstat to escalate privileges.

    Published: 5 Dec 2019
    7.2
    High

    CVE-2019-19007

    Last Modified: 21 Nov 2024

    Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled, a related issue to CVE-2019-17600.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19594

    Last Modified: 21 Nov 2024

    reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19595

    Last Modified: 21 Nov 2024

    reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

    Published: 5 Dec 2019
    7.4
    High

    CVE-2013-0243

    Last Modified: 21 Nov 2024

    haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections

    Published: 5 Dec 2019
    —
    Unknown

    CVE-2019-19008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-19363. Reason: This candidate is a reservation duplicate of CVE-2019-19363. Notes: All CVE users should reference CVE-2019-19363 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Dec 2019
    5.3
    Medium

    CVE-2019-18180

    Last Modified: 21 Nov 2024

    Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attaching files to mails) of ((OTRS)) Community Edition and OTRS allows an remote attacker to cause an endless loop. This issue affects: OTRS AG: ((OTRS)) Community Edition 5.0.x version 5.0.38 and prior versions; 6.0.x version 6.0.23 and prior versions. OTRS AG: OTRS 7.0.x version 7.0.12 and prior versions.

    Published: 5 Dec 2019
    7.8
    High

    CVE-2019-17437

    Last Modified: 21 Nov 2024

    An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0.20; 8.1 versions prior to 8.1.11; 9.0 versions prior to 9.0.5. PAN-OS version 7.0 and prior EOL versions have not been evaluated for this issue.

    Published: 5 Dec 2019
    7.8
    High

    CVE-2019-19601

    Last Modified: 21 Nov 2024

    OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19589

    Last Modified: 21 Nov 2024

    The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the file upload process. It only serves the uploaded PDF files and the responsibility of uploading PDF file remains with the Site owner of Wordpress installation, the upload of PDF file is managed by Wordpress core and not by PDF Embedder Plugin. Control & block of polyglot file is required to be taken care at the time of upload, not on showing the file. Moreover, the reference mentions retrieving the files from the browser cache and manually renaming it to jar for executing the file. That refers to a two step non-connected steps which has nothing to do with PDF Embedder.

    Published: 5 Dec 2019
    8.8
    High

    CVE-2019-19597

    Last Modified: 21 Nov 2024

    D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

    Published: 5 Dec 2019
    8.8
    High

    CVE-2019-19598

    Last Modified: 21 Nov 2024

    D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If this value is equal to the value stored in the device's /var/hnap/timestamp file, the request will pass the HNAP_AUTH check function.

    Published: 5 Dec 2019
    5.4
    Medium

    CVE-2019-19596

    Last Modified: 21 Nov 2024

    GitBook through 2.6.9 allows XSS via a local .md file.

    Published: 5 Dec 2019