CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2020-1728

    Last Modified: 21 Nov 2024

    A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors.

    Published: 27 Nov 2019
    7.5
    High

    CVE-2011-4310

    Last Modified: 21 Nov 2024

    The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2011-1939

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2011-1934

    Last Modified: 21 Nov 2024

    lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2011-1933

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Jifty::DBI before 0.68.

    Published: 26 Nov 2019
    8.8
    High

    CVE-2019-17590

    Last Modified: 21 Nov 2024

    The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and dispersing it to a victim via social engineering, enticing them to click the link. Once the user/victim clicks the "try again" button, the attacker can take over the account and perform unintended actions on the victim's behalf. NOTE: A third-party maintainer has stated that this CVE is a false report. They state that the csrf_callback function is actually a callback function to the callers own handler for output. The function called can be changed via configuration to a custom callback to handle failed validation differently. They also stated that there is no way for an attacker to change tokens to make them valid from the client side. The only thing an attack can do is to pull the token out of the javascript, but that will always be possible and has nothing to do with the callback

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2019-17392

    Last Modified: 21 Nov 2024

    Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-16388

    Last Modified: 21 Nov 2024

    PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect

    Published: 26 Nov 2019
    8.1
    High

    CVE-2019-16387

    Last Modified: 21 Nov 2024

    PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-16386

    Last Modified: 21 Nov 2024

    PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-16195

    Last Modified: 21 Nov 2024

    Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18446

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18447

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.

    Published: 26 Nov 2019
    6.5
    Medium

    CVE-2019-18448

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18449

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18450

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-18451

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

    Published: 26 Nov 2019
    5.3
    Medium

    CVE-2019-18452

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.

    Published: 26 Nov 2019
    10
    Critical

    CVE-2019-18580

    Last Modified: 21 Nov 2024

    Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18453

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.

    Published: 26 Nov 2019
    5.4
    Medium

    CVE-2019-14449

    Last Modified: 21 Nov 2024

    An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-18454

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

    Published: 26 Nov 2019
    7.5
    High

    CVE-2019-18455

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries. It has a large or infinite loop.

    Published: 26 Nov 2019
    5.3
    Medium

    CVE-2019-18456

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).

    Published: 26 Nov 2019
    8.8
    High

    CVE-2019-4387

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 162715.

    Published: 26 Nov 2019
    6.5
    Medium

    CVE-2019-15687

    Last Modified: 21 Nov 2024

    Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version of the product, host unique ID). Information Disclosure.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-15686

    Last Modified: 21 Nov 2024

    Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-15685

    Last Modified: 21 Nov 2024

    Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass.

    Published: 26 Nov 2019
    8.8
    High

    CVE-2019-18457

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.

    Published: 26 Nov 2019
    2.7
    Low

    CVE-2019-18458

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

    Published: 26 Nov 2019
    6.8
    Medium

    CVE-2019-16241

    Last Modified: 21 Nov 2024

    On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock screen checks for the existence of a specific file and disables PIN authentication if it exists. This file would typically be created via Android Debug Bridge (adb) over USB.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-15688

    Last Modified: 21 Nov 2024

    Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.

    Published: 26 Nov 2019
    5.4
    Medium

    CVE-2016-9271

    Last Modified: 21 Nov 2024

    Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-16243

    Last Modified: 21 Nov 2024

    On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the device's firmware over-the-air update settings. (This web API is normally used by the system application to trigger firmware updates via OmaService.js.)

    Published: 26 Nov 2019
    6.8
    Medium

    CVE-2019-16242

    Last Modified: 21 Nov 2024

    On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary OS commands as the root user via the application's UI.

    Published: 26 Nov 2019
    8.8
    High

    CVE-2017-7399

    Last Modified: 21 Nov 2024

    Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2019-19129

    Last Modified: 21 Nov 2024

    Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.

    Published: 26 Nov 2019
    5.3
    Medium

    CVE-2019-18459

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).

    Published: 26 Nov 2019
    8.3
    High

    CVE-2019-7319

    Last Modified: 21 Nov 2024

    An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBackend, PamBackend, SpnegoDjangoBackend, RemoteUserDjangoBackend, SAML2Backend, OpenIDBackend, or OAuthBackend, external users are created with superuser privileges.

    Published: 26 Nov 2019
    8.3
    High

    CVE-2018-20090

    Last Modified: 21 Nov 2024

    An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2019-19307

    Last Modified: 21 Nov 2024

    An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.

    Published: 26 Nov 2019
    5.4
    Medium

    CVE-2015-9537

    Last Modified: 21 Nov 2024

    The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.

    Published: 26 Nov 2019
    6.5
    Medium

    CVE-2015-9538

    Last Modified: 21 Nov 2024

    The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.

    Published: 26 Nov 2019
    6.1
    Medium

    CVE-2015-9539

    Last Modified: 21 Nov 2024

    The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.

    Published: 26 Nov 2019
    5.4
    Medium

    CVE-2019-19306

    Last Modified: 21 Nov 2024

    The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2019-6675

    Last Modified: 21 Nov 2024

    BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. This issue only impacts specific engineering hotfixes using the aforementioned authentication configuration. NOTE: This vulnerability does not affect any of the BIG-IP major, minor or maintenance releases you obtained from downloads.f5.com. The affected Engineering Hotfix builds are as follows: Hotfix-BIGIP-14.1.0.3.0.79.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.97.6-ENG.iso, Hotfix-BIGIP-14.1.0.3.0.99.6-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.15.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.36.5-ENG.iso, Hotfix-BIGIP-14.1.0.5.0.40.5-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.11.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.14.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.68.9-ENG.iso, Hotfix-BIGIP-14.1.0.6.0.70.9-ENG.iso, Hotfix-BIGIP-14.1.2.0.11.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.18.37-ENG.iso, Hotfix-BIGIP-14.1.2.0.32.37-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.46.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.14.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.16.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.34.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.97.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.99.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.105.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.111.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.115.4-ENG.iso, Hotfix-BIGIP-14.1.2.1.0.122.4-ENG.iso, Hotfix-BIGIP-15.0.1.0.33.11-ENG.iso, Hotfix-BIGIP-15.0.1.0.48.11-ENG.iso

    Published: 26 Nov 2019
    7.5
    High

    CVE-2019-18460

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18461

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.

    Published: 26 Nov 2019
    4.3
    Medium

    CVE-2019-18462

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.

    Published: 26 Nov 2019
    9.8
    Critical

    CVE-2019-12489

    Last Modified: 21 Nov 2024

    An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mount parameter.

    Published: 26 Nov 2019