CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-18667

    Last Modified: 21 Nov 2024

    /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.

    Published: 2 Nov 2019
    5.4
    Medium

    CVE-2019-18664

    Last Modified: 21 Nov 2024

    The Log module in SECUDOS DOMOS before 5.6 allows XSS.

    Published: 2 Nov 2019
    7.5
    High

    CVE-2019-18665

    Last Modified: 21 Nov 2024

    The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.

    Published: 2 Nov 2019
    9.8
    Critical

    CVE-2019-18662

    Last Modified: 21 Nov 2024

    An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

    Published: 2 Nov 2019
    7.5
    High

    CVE-2019-18661

    Last Modified: 21 Nov 2024

    Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console.

    Published: 2 Nov 2019
    5.3
    Medium

    CVE-2019-18659

    Last Modified: 21 Nov 2024

    The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are affected by design (e.g., use of Android versus iOS does not matter); testing in an open RF environment is, of course, contraindicated.

    Published: 2 Nov 2019
    8.1
    High

    CVE-2005-2352

    Last Modified: 20 Nov 2024

    I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2013-4168

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2019-18654

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

    Published: 1 Nov 2019
    5.5
    Medium

    CVE-2013-0180

    Last Modified: 21 Nov 2024

    Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

    Published: 1 Nov 2019
    5.5
    Medium

    CVE-2013-0178

    Last Modified: 21 Nov 2024

    Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2019-18653

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2005-2350

    Last Modified: 20 Nov 2024

    Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2010-3661

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

    Published: 1 Nov 2019
    5.4
    Medium

    CVE-2010-3660

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.

    Published: 1 Nov 2019
    7.5
    High

    CVE-2013-2227

    Last Modified: 21 Nov 2024

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

    Published: 1 Nov 2019
    9.8
    Critical

    CVE-2013-1666

    Last Modified: 21 Nov 2024

    Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2019-12752

    Last Modified: 21 Nov 2024

    The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attacker to circumvent the existing tamper protection in use on the resident system.

    Published: 1 Nov 2019
    4.3
    Medium

    CVE-2019-6658

    Last Modified: 21 Nov 2024

    On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack.

    Published: 1 Nov 2019
    6.1
    Medium

    CVE-2019-6657

    Last Modified: 21 Nov 2024

    On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility.

    Published: 1 Nov 2019
    7.2
    High

    CVE-2019-15588

    Last Modified: 21 Nov 2024

    There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.

    Published: 1 Nov 2019
    7.5
    High

    CVE-2012-2979

    Last Modified: 21 Nov 2024

    FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.

    Published: 1 Nov 2019
    9.8
    Critical

    CVE-2005-3056

    Last Modified: 21 Nov 2024

    TWiki allows arbitrary shell command execution via the Include function

    Published: 1 Nov 2019
    8.1
    High

    CVE-2013-4751

    Last Modified: 21 Nov 2024

    php-symfony2-Validator has loss of information during serialization

    Published: 1 Nov 2019
    9.8
    Critical

    CVE-2013-2739

    Last Modified: 21 Nov 2024

    MiniDLNA has heap-based buffer overflow

    Published: 1 Nov 2019
    9.8
    Critical

    CVE-2013-2738

    Last Modified: 21 Nov 2024

    minidlna has SQL Injection that may allow retrieval of arbitrary files

    Published: 1 Nov 2019
    7.5
    High

    CVE-2013-2600

    Last Modified: 21 Nov 2024

    MiniUPnPd has information disclosure use of snprintf()

    Published: 1 Nov 2019
    5.4
    Medium

    CVE-2019-18636

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.

    Published: 1 Nov 2019
    4.3
    Medium

    CVE-2019-16909

    Last Modified: 21 Nov 2024

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects (with authentication as a Jira user, but without authorization for specific projects) via the plugins/servlet/nfj/NotificationSettings URI.

    Published: 1 Nov 2019
    5.3
    Medium

    CVE-2019-16908

    Last Modified: 21 Nov 2024

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

    Published: 1 Nov 2019
    7.1
    High

    CVE-2019-15791

    Last Modified: 21 Nov 2024

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to a refcount underflow.

    Published: 1 Nov 2019
    5.3
    Medium

    CVE-2019-16907

    Last Modified: 21 Nov 2024

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-16906

    Last Modified: 21 Nov 2024

    An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the normal user.

    Published: 31 Oct 2019
    7.8
    High

    CVE-2019-16675

    Last Modified: 21 Nov 2024

    An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-18226

    Last Modified: 21 Nov 2024

    Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-18230

    Last Modified: 21 Nov 2024

    Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-18228

    Last Modified: 21 Nov 2024

    Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.

    Published: 31 Oct 2019
    6.5
    Medium

    CVE-2019-18229

    Last Modified: 21 Nov 2024

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Lack of sanitization of user-supplied input cause SQL injection vulnerabilities. An attacker can leverage these vulnerabilities to disclose information.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-18227

    Last Modified: 21 Nov 2024

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

    Published: 31 Oct 2019
    4.6
    Medium

    CVE-2019-16295

    Last Modified: 21 Nov 2024

    Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-13547

    Last Modified: 21 Nov 2024

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-13508

    Last Modified: 21 Nov 2024

    FreeTDS through 1.1.11 has a Buffer Overflow.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-13551

    Last Modified: 21 Nov 2024

    Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnerabilities to remotely execute code while posing as an administrator.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2012-6125

    Last Modified: 21 Nov 2024

    Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2012-6124

    Last Modified: 21 Nov 2024

    A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."

    Published: 31 Oct 2019
    6.5
    Medium

    CVE-2012-6123

    Last Modified: 21 Nov 2024

    Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

    Published: 31 Oct 2019
    7.5
    High

    CVE-2012-6122

    Last Modified: 21 Nov 2024

    Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.

    Published: 31 Oct 2019
    8.8
    High

    CVE-2013-2075

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. NOTE: this issue exists because of an incomplete fix for CVE-2012-6122.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2018-4002

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. When parsing labels in mDNS packets, the firewall unsafely handles label compression pointers, leading to an uncontrolled recursion that eventually exhausts the stack, crashing the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.

    Published: 31 Oct 2019
    7.8
    High

    CVE-2018-3983

    Last Modified: 21 Nov 2024

    An exploitable uninitialized pointer vulnerability exists in the Word document parser of the the Atlantis Word Processor. A specially crafted document can cause an array fetch to return an uninitialized pointer and then performs some arithmetic before writing a value to the result. Usage of this uninitialized pointer can allow an attacker to corrupt heap memory resulting in code execution under the context of the application. An attacker must convince a victim to open a document in order to trigger this vulnerability.

    Published: 31 Oct 2019