CVE Feed

    Dashboard / CVE

    9.9
    Critical

    CVE-2019-16541

    Last Modified: 21 Nov 2024

    Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2019-6852

    Last Modified: 28 May 2026

    A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2019-6853

    Last Modified: 21 Nov 2024

    A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server.

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2013-2093

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2013-2092

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2013-2091

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2013-1817

    Last Modified: 21 Nov 2024

    MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2013-1816

    Last Modified: 21 Nov 2024

    MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2011-4455

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting vulnerabilities in Tiki 7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-admin_system.php, (2) tiki-pagehistory.php, (3) tiki-removepage.php, or (4) tiki-rename_page.php.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2011-4454

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.

    Published: 20 Nov 2019
    7.8
    High

    CVE-2019-3466

    Last Modified: 21 Nov 2024

    The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2019-18858

    Last Modified: 21 Nov 2024

    CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2010-4659

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.

    Published: 20 Nov 2019
    8.8
    High

    CVE-2019-4561

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.0 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 166456.

    Published: 20 Nov 2019
    6.5
    Medium

    CVE-2019-4530

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they should not normally be able to. IBM X-Force ID: 165586.

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2010-4660

    Last Modified: 21 Nov 2024

    Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2019-10765

    Last Modified: 21 Nov 2024

    iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2011-0529

    Last Modified: 21 Nov 2024

    Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

    Published: 20 Nov 2019
    7.7
    High

    CVE-2019-5542

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain a denial-of-service vulnerability in the RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to create a denial-of-service condition on their own VM.

    Published: 20 Nov 2019
    9.1
    Critical

    CVE-2019-5541

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM.

    Published: 20 Nov 2019
    7.7
    High

    CVE-2019-5540

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process.

    Published: 20 Nov 2019
    9.8
    Critical

    CVE-2011-1028

    Last Modified: 21 Nov 2024

    The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2013-0195

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2013-0194

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2013-0193

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2019-16200

    Last Modified: 21 Nov 2024

    GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represented in 32 bit binary, evaluates to a negative number. The problem exists in the http_cgi_write function under http-cgi.c; however, exploitation might show svz_envblock_add in libserveez/passthrough.c as the location of the heap-based buffer over-read.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2019-15072

    Last Modified: 21 Nov 2024

    The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2019-15073

    Last Modified: 21 Nov 2024

    An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.

    Published: 20 Nov 2019
    6.1
    Medium

    CVE-2019-15071

    Last Modified: 21 Nov 2024

    The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.

    Published: 20 Nov 2019
    7.8
    High

    CVE-2019-6191

    Last Modified: 21 Nov 2024

    A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.

    Published: 20 Nov 2019
    7.8
    High

    CVE-2019-6189

    Last Modified: 21 Nov 2024

    A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.

    Published: 20 Nov 2019
    6.5
    Medium

    CVE-2019-6187

    Last Modified: 21 Nov 2024

    A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

    Published: 20 Nov 2019
    8.8
    High

    CVE-2019-6186

    Last Modified: 21 Nov 2024

    A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.

    Published: 20 Nov 2019
    7.8
    High

    CVE-2019-6184

    Last Modified: 21 Nov 2024

    A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2019-6176

    Last Modified: 21 Nov 2024

    A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.

    Published: 20 Nov 2019
    7.5
    High

    CVE-2019-6477

    Last Modified: 21 Nov 2024

    With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is closed, the load on the server releasing these multiple resources can cause it to become unresponsive, even for queries that can be answered authoritatively or from cache. (This is most likely to be perceived as an intermittent server problem).

    Published: 20 Nov 2019
    5.5
    Medium

    CVE-2019-19039

    Last Modified: 21 Nov 2024

    __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel provide facilities to restrict access to dmesg - dmesg_restrict=1 sysctl option. So it's really up to the system administrator to judge whether dmesg access shall be disallowed or not. 2) WARN/WARN_ON are widely used macros in the linux kernel. If this CVE is considered valid this would mean there are literally thousands CVE lurking in the kernel - something which clearly is not the case.

    Published: 20 Nov 2019
    7
    High

    CVE-2019-14898

    Last Modified: 21 Nov 2024

    The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.

    Published: 20 Nov 2019
    4.8
    Medium

    CVE-2011-3352

    Last Modified: 21 Nov 2024

    Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.

    Published: 19 Nov 2019
    9.8
    Critical

    CVE-2011-3350

    Last Modified: 21 Nov 2024

    masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.

    Published: 19 Nov 2019
    7.8
    High

    CVE-2011-3349

    Last Modified: 21 Nov 2024

    lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.

    Published: 19 Nov 2019
    5.3
    Medium

    CVE-2019-10083

    Last Modified: 21 Nov 2024

    When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.

    Published: 19 Nov 2019
    8.8
    High

    CVE-2019-12421

    Last Modified: 21 Nov 2024

    When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiFi invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be used for up to 12 hours after logging out to make API requests to NiFi.

    Published: 19 Nov 2019
    6.5
    Medium

    CVE-2019-10080

    Last Modified: 21 Nov 2024

    The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI instance uses.

    Published: 19 Nov 2019
    9.8
    Critical

    CVE-2019-10766

    Last Modified: 21 Nov 2024

    Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.

    Published: 19 Nov 2019
    8.6
    High

    CVE-2019-11289

    Last Modified: 21 Nov 2024

    Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.

    Published: 19 Nov 2019
    7.8
    High

    CVE-2011-2922

    Last Modified: 21 Nov 2024

    ktsuss versions 1.4 and prior spawns the GTK interface to run as root. This can allow a local attacker to escalate privileges to root and use the "GTK_MODULES" environment variable to possibly execute arbitrary code.

    Published: 19 Nov 2019
    7.3
    High

    CVE-2019-18934

    Last Modified: 21 Nov 2024

    Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.

    Published: 19 Nov 2019
    9.8
    Critical

    CVE-2011-2921

    Last Modified: 21 Nov 2024

    ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.

    Published: 19 Nov 2019
    7.5
    High

    CVE-2012-6071

    Last Modified: 21 Nov 2024

    nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

    Published: 19 Nov 2019