CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-13704

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 22 Oct 2019
    6.5
    Medium

    CVE-2019-13713

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13716

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-16404

    Last Modified: 21 Nov 2024

    Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16974

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16969

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-17220

    Last Modified: 21 Nov 2024

    Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16970

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16968

    Last Modified: 21 Nov 2024

    An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16967

    Last Modified: 21 Nov 2024

    An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16966

    Last Modified: 21 Nov 2024

    An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. It can be requested via a GET request to /admin/ajax.php?module=contactmanager.

    Published: 21 Oct 2019
    7.2
    High

    CVE-2019-16965

    Last Modified: 21 Nov 2024

    resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.

    Published: 21 Oct 2019
    7.8
    High

    CVE-2019-9491

    Last Modified: 21 Nov 2024

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.

    Published: 21 Oct 2019
    8.8
    High

    CVE-2019-16964

    Last Modified: 21 Nov 2024

    app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit) to execute any commands on the host as www-data.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-18203

    Last Modified: 21 Nov 2024

    On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

    Published: 21 Oct 2019
    9.8
    Critical

    CVE-2019-18225

    Last Modified: 21 Nov 2024

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance administrative access. These products formerly used the NetScaler brand name.

    Published: 21 Oct 2019
    —
    Unknown

    CVE-2019-8370

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Oct 2019
    —
    Unknown

    CVE-2019-8369

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16988

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16991

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16989

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.5
    Medium

    CVE-2019-16986

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which takes any pathname and allows a download of it. (resources\secure_download.php is also affected.)

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16987

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.5
    Medium

    CVE-2019-16985

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16984

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16983

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16981

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16982

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    6.5
    Medium

    CVE-2019-16990

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from the URL, which takes any pathname (base64 encoded) and allows a download of it.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16979

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 21 Oct 2019
    8.8
    High

    CVE-2019-16980

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16978

    Last Modified: 21 Nov 2024

    In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

    Published: 21 Oct 2019
    7.2
    High

    CVE-2019-16530

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

    Published: 21 Oct 2019
    7.5
    High

    CVE-2019-18217

    Last Modified: 21 Nov 2024

    ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-16862

    Last Modified: 21 Nov 2024

    Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.

    Published: 21 Oct 2019
    6.1
    Medium

    CVE-2019-17409

    Last Modified: 21 Nov 2024

    Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.

    Published: 21 Oct 2019
    7.5
    High

    CVE-2019-20637

    Last Modified: 21 Nov 2024

    An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.

    Published: 21 Oct 2019
    7.5
    High

    CVE-2019-17400

    Last Modified: 21 Nov 2024

    The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.

    Published: 21 Oct 2019
    7.7
    High

    CVE-2019-10716

    Last Modified: 21 Nov 2024

    An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.

    Published: 20 Oct 2019
    5.4
    Medium

    CVE-2019-10715

    Last Modified: 21 Nov 2024

    There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.

    Published: 20 Oct 2019
    6.8
    Medium

    CVE-2019-18216

    Last Modified: 21 Nov 2024

    The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in which booting from a USB device is prohibited. Attackers who have physical laptop access can exhaust the main battery to reset the BIOS configuration, and then achieve direct access to the hard drive by booting a live USB OS without disassembling the laptop. NOTE: the vendor has apparently indicated that this is "normal" and use of the same battery for the BIOS and the overall system is a "new design." However, the vendor apparently plans to "improve" this an unspecified later time

    Published: 20 Oct 2019
    7.7
    High

    CVE-2019-18214

    Last Modified: 21 Nov 2024

    The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)

    Published: 19 Oct 2019
    6.1
    Medium

    CVE-2019-18209

    Last Modified: 21 Nov 2024

    templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.

    Published: 19 Oct 2019
    5.3
    Medium

    CVE-2019-18202

    Last Modified: 21 Nov 2024

    Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.

    Published: 19 Oct 2019
    5.4
    Medium

    CVE-2019-4409

    Last Modified: 21 Nov 2024

    HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.

    Published: 18 Oct 2019
    7.8
    High

    CVE-2019-13541

    Last Modified: 21 Nov 2024

    In Horner Automation Cscape 9.90 and prior, an improper input validation vulnerability has been identified that may be exploited by processing files lacking user input validation. This may allow an attacker to access information and remotely execute arbitrary code.

    Published: 18 Oct 2019
    7.8
    High

    CVE-2019-13545

    Last Modified: 21 Nov 2024

    In Horner Automation Cscape 9.90 and prior, improper validation of data may cause the system to write outside the intended buffer area, which may allow arbitrary code execution.

    Published: 18 Oct 2019
    8.8
    High

    CVE-2019-17367

    Last Modified: 21 Nov 2024

    OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.

    Published: 18 Oct 2019
    9.8
    Critical

    CVE-2019-17526

    Last Modified: 21 Nov 2024

    An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE: the vendor's position is that the product is "vulnerable by design" and the current behavior will be retained

    Published: 18 Oct 2019
    9.8
    Critical

    CVE-2019-17393

    Last Modified: 21 Nov 2024

    The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.

    Published: 18 Oct 2019