CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-1313

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376.

    Published: 10 Oct 2019
    6.8
    Medium

    CVE-2019-1314

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'.

    Published: 10 Oct 2019
    7.8
    High

    CVE-2019-1315

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

    Published: 10 Oct 2019
    6.8
    Medium

    CVE-2019-1230

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-1307

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1308, CVE-2019-1335, CVE-2019-1366.

    Published: 10 Oct 2019
    5.4
    Medium

    CVE-2019-17434

    Last Modified: 21 Nov 2024

    LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.

    Published: 10 Oct 2019
    4.8
    Medium

    CVE-2019-17433

    Last Modified: 21 Nov 2024

    z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-17431

    Last Modified: 21 Nov 2024

    An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-17432

    Last Modified: 21 Nov 2024

    An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-17072

    Last Modified: 21 Nov 2024

    The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17071

    Last Modified: 21 Nov 2024

    The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17070

    Last Modified: 21 Nov 2024

    The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-17429

    Last Modified: 21 Nov 2024

    Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17430

    Last Modified: 21 Nov 2024

    EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17427

    Last Modified: 21 Nov 2024

    In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.

    Published: 10 Oct 2019
    9.1
    Critical

    CVE-2019-17426

    Last Modified: 21 Nov 2024

    Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

    Published: 10 Oct 2019
    —
    Unknown

    CVE-2019-17441

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-10936

    Last Modified: 21 Nov 2024

    Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticated remote attacker to trigger a denial of service condition.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-13693

    Last Modified: 21 Nov 2024

    Use after free in IndexedDB in Google Chrome prior to 77.0.3865.120 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

    Published: 10 Oct 2019
    5.4
    Medium

    CVE-2019-15587

    Last Modified: 21 Nov 2024

    In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-13695

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-13696

    Last Modified: 21 Nov 2024

    Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-13697

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 10 Oct 2019
    3.3
    Low

    CVE-2020-27774

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 10 Oct 2019
    —
    Unknown

    CVE-2019-17438

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2019
    —
    Unknown

    CVE-2019-17439

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2019
    —
    Unknown

    CVE-2019-17442

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2019
    —
    Unknown

    CVE-2019-17443

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 10 Oct 2019
    7.8
    High

    CVE-2019-20079

    Last Modified: 21 Nov 2024

    The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.

    Published: 10 Oct 2019
    3.3
    Low

    CVE-2020-27767

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 10 Oct 2019
    3.3
    Low

    CVE-2020-27769

    Last Modified: 21 Nov 2024

    In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.

    Published: 10 Oct 2019
    3.3
    Low

    CVE-2020-27773

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-13694

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Oct 2019
    5.3
    Medium

    CVE-2019-17420

    Last Modified: 21 Nov 2024

    In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.

    Published: 9 Oct 2019
    7.2
    High

    CVE-2019-17418

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.

    Published: 9 Oct 2019
    7.2
    High

    CVE-2019-17419

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.

    Published: 9 Oct 2019
    4.8
    Medium

    CVE-2019-17417

    Last Modified: 21 Nov 2024

    PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.

    Published: 9 Oct 2019
    9.8
    Critical

    CVE-2019-17415

    Last Modified: 21 Nov 2024

    A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.

    Published: 9 Oct 2019
    7.5
    High

    CVE-2019-17414

    Last Modified: 21 Nov 2024

    tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.

    Published: 9 Oct 2019
    6.5
    Medium

    CVE-2019-17109

    Last Modified: 21 Nov 2024

    Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-17365

    Last Modified: 15 Jan 2025

    Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.

    Published: 9 Oct 2019
    8.8
    High

    CVE-2019-17366

    Last Modified: 21 Nov 2024

    Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5699

    Last Modified: 21 Nov 2024

    NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5700

    Last Modified: 21 Nov 2024

    NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5046

    Last Modified: 21 Nov 2024

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5048

    Last Modified: 21 Nov 2024

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5050

    Last Modified: 21 Nov 2024

    A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5045

    Last Modified: 21 Nov 2024

    A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5047

    Last Modified: 21 Nov 2024

    An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker can craft a malicious PDF to trigger this vulnerability.

    Published: 9 Oct 2019
    7.8
    High

    CVE-2019-5053

    Last Modified: 21 Nov 2024

    An exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a use-after-free condition. An attacker can craft a malicious PDF to trigger this vulnerability.

    Published: 9 Oct 2019