CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-2765

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data as well as unauthorized read access to a subset of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L).

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-2734

    Last Modified: 21 Nov 2024

    Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Execute on DBMS_ADVISOR privilege with network access via OracleNet to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Core RDBMS accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

    Published: 16 Oct 2019
    5
    Medium

    CVE-2018-2875

    Last Modified: 21 Nov 2024

    Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Core RDBMS accessible data. CVSS 3.0 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).

    Published: 16 Oct 2019
    5.4
    Medium

    CVE-2018-3300

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Internal Operations). The supported version that is affected is 7.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Office. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Xstore Office accessible data as well as unauthorized read access to a subset of Oracle Retail Xstore Office accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

    Published: 16 Oct 2019
    5.9
    Medium

    CVE-2019-2896

    Last Modified: 21 Nov 2024

    Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations). Supported versions that are affected are 7.1.0, 15.0.0, 16.0.0, 17.0.0, and 18.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MICROS Relate CRM Software. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MICROS Relate CRM Software accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

    Published: 16 Oct 2019
    5.4
    Medium

    CVE-2019-17577

    Last Modified: 21 Nov 2024

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

    Published: 16 Oct 2019
    5.4
    Medium

    CVE-2019-17578

    Last Modified: 21 Nov 2024

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

    Published: 16 Oct 2019
    9.8
    Critical

    CVE-2019-17662

    Last Modified: 21 Nov 2024

    ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

    Published: 16 Oct 2019
    5.7
    Medium

    CVE-2019-6474

    Last Modified: 21 Nov 2024

    A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart. If the number of such leases exceeds a hard-coded limit in the Kea code, a server trying to restart will conclude that there is a problem with its lease store and give up. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-6473

    Last Modified: 21 Nov 2024

    An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exit. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-6472

    Last Modified: 21 Nov 2024

    A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2.

    Published: 16 Oct 2019
    6.1
    Medium

    CVE-2019-17660

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/336819/lang/ PATH_INFO.

    Published: 16 Oct 2019
    9.8
    Critical

    CVE-2019-6334

    Last Modified: 21 Nov 2024

    HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signature that may allow potential execution of arbitrary code.

    Published: 16 Oct 2019
    4.8
    Medium

    CVE-2019-16522

    Last Modified: 21 Nov 2024

    The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.

    Published: 16 Oct 2019
    6.1
    Medium

    CVE-2019-16521

    Last Modified: 21 Nov 2024

    The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.

    Published: 16 Oct 2019
    5.4
    Medium

    CVE-2019-16523

    Last Modified: 21 Nov 2024

    The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.

    Published: 16 Oct 2019
    5.4
    Medium

    CVE-2019-16520

    Last Modified: 21 Nov 2024

    The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10456

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10457

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    9.9
    Critical

    CVE-2019-10458

    Last Modified: 21 Nov 2024

    Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10454

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10455

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    7.8
    High

    CVE-2019-10453

    Last Modified: 21 Nov 2024

    Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10452

    Last Modified: 21 Nov 2024

    Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    3.3
    Low

    CVE-2019-10450

    Last Modified: 21 Nov 2024

    Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10451

    Last Modified: 21 Nov 2024

    Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 16 Oct 2019
    8.8
    High

    CVE-2019-10449

    Last Modified: 21 Nov 2024

    Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    8.8
    High

    CVE-2019-10448

    Last Modified: 21 Nov 2024

    Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10447

    Last Modified: 21 Nov 2024

    Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    8.2
    High

    CVE-2019-10446

    Last Modified: 21 Nov 2024

    Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10445

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10442

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    8.8
    High

    CVE-2019-10443

    Last Modified: 21 Nov 2024

    Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-10444

    Last Modified: 21 Nov 2024

    Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10441

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 16 Oct 2019
    8.8
    High

    CVE-2019-10440

    Last Modified: 21 Nov 2024

    Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

    Published: 16 Oct 2019
    4.3
    Medium

    CVE-2019-10439

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-10438

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 16 Oct 2019
    8.8
    High

    CVE-2019-10437

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-10436

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.

    Published: 16 Oct 2019
    7.8
    High

    CVE-2019-4031

    Last Modified: 21 Nov 2024

    IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to write files as root in the file system, which could allow the attacker to gain root privileges. IBM X-Force ID: 155997.

    Published: 16 Oct 2019
    7.2
    High

    CVE-2019-15893

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.

    Published: 16 Oct 2019
    4.8
    Medium

    CVE-2019-17629

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.

    Published: 16 Oct 2019
    4.8
    Medium

    CVE-2019-17630

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2019-17627

    Last Modified: 21 Nov 2024

    The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale ZEN-R lock and unspecified other locks.

    Published: 16 Oct 2019
    9
    Critical

    CVE-2019-17625

    Last Modified: 21 Nov 2024

    There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.

    Published: 16 Oct 2019
    7.8
    High

    CVE-2019-17624

    Last Modified: 21 Nov 2024

    "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow.

    Published: 16 Oct 2019
    9.8
    Critical

    CVE-2016-11014

    Last Modified: 21 Nov 2024

    NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

    Published: 16 Oct 2019
    6.5
    Medium

    CVE-2016-11015

    Last Modified: 21 Nov 2024

    NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.

    Published: 16 Oct 2019
    6.1
    Medium

    CVE-2016-11016

    Last Modified: 21 Nov 2024

    NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.

    Published: 16 Oct 2019