CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2015-9452

    Last Modified: 15 Jan 2025

    The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2015-9451

    Last Modified: 21 Nov 2024

    The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2015-9450

    Last Modified: 21 Nov 2024

    The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-12812

    Last Modified: 21 Nov 2024

    MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-12811

    Last Modified: 21 Nov 2024

    ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for code execution

    Published: 7 Oct 2019
    5.1
    Medium

    CVE-2019-3688

    Last Modified: 21 Nov 2024

    The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by changing the binary

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-15751

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.

    Published: 7 Oct 2019
    6.1
    Medium

    CVE-2019-15750

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-15749

    Last Modified: 21 Nov 2024

    SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-15748

    Last Modified: 21 Nov 2024

    SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could execute arbitrary PHP code.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-15747

    Last Modified: 21 Nov 2024

    SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to insufficient checks on the server side.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-15746

    Last Modified: 21 Nov 2024

    SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.

    Published: 7 Oct 2019
    6.1
    Medium

    CVE-2018-18379

    Last Modified: 21 Nov 2024

    The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.

    Published: 7 Oct 2019
    7.4
    High

    CVE-2019-16263

    Last Modified: 21 Nov 2024

    The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-life product.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-17451

    Last Modified: 21 Nov 2024

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

    Published: 7 Oct 2019
    5.5
    Medium

    CVE-2019-18806

    Last Modified: 21 Nov 2024

    A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel before 5.3.5 allows local users to cause a denial of service (memory consumption) by triggering pci_dma_mapping_error() failures, aka CID-1acb8f2a7a9f.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-14854

    Last Modified: 21 Nov 2024

    OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-18799

    Last Modified: 21 Nov 2024

    LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.

    Published: 7 Oct 2019
    5.3
    Medium

    CVE-2019-14845

    Last Modified: 21 Nov 2024

    A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.

    Published: 7 Oct 2019
    3.3
    Low

    CVE-2020-27751

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-18797

    Last Modified: 21 Nov 2024

    LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2019-18798

    Last Modified: 21 Nov 2024

    LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.

    Published: 7 Oct 2019
    3.3
    Low

    CVE-2020-27761

    Last Modified: 21 Nov 2024

    WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch casts to `ssize_t` instead to avoid this issue. Red Hat Product Security marked the Severity as Low because although it could potentially lead to an impact to application availability, no specific impact was shown in this case. This flaw affects ImageMagick versions prior to ImageMagick 7.0.9-0.

    Published: 7 Oct 2019
    9.8
    Critical

    CVE-2019-17269

    Last Modified: 21 Nov 2024

    Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.

    Published: 6 Oct 2019
    3.3
    Low

    CVE-2019-17264

    Last Modified: 21 Nov 2024

    In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-based buffer over-read because an incorrect variable name is used for a certain offset. NOTE: the vendor has disputed this as described in the GitHub issue

    Published: 6 Oct 2019
    3.3
    Low

    CVE-2019-17263

    Last Modified: 21 Nov 2024

    In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap-based buffer over-read because rejection of an unsupported size only considers values less than 6, even though values of 6 and 7 are also unsupported. NOTE: the vendor has disputed this as described in the GitHub issue

    Published: 6 Oct 2019
    9.8
    Critical

    CVE-2019-17240

    Last Modified: 21 Nov 2024

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

    Published: 6 Oct 2019
    4.8
    Medium

    CVE-2019-17226

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.

    Published: 6 Oct 2019
    5.4
    Medium

    CVE-2019-17225

    Last Modified: 21 Nov 2024

    Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.

    Published: 6 Oct 2019
    9.8
    Critical

    CVE-2019-17215

    Last Modified: 21 Nov 2024

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforce protection (e.g., lockout) established. An attacker might be able to bruteforce the password to authenticate on the device.

    Published: 6 Oct 2019
    9.8
    Critical

    CVE-2019-17216

    Last Modified: 21 Nov 2024

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authentication uses MD5 to hash passwords. Cracking is possible with minimal effort.

    Published: 6 Oct 2019
    8.8
    High

    CVE-2019-17217

    Last Modified: 21 Nov 2024

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.

    Published: 6 Oct 2019
    9.1
    Critical

    CVE-2019-17218

    Last Modified: 21 Nov 2024

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the communication to the web service is unencrypted via http. An attacker is able to intercept and sniff communication to the web service.

    Published: 6 Oct 2019
    8.8
    High

    CVE-2019-17219

    Last Modified: 21 Nov 2024

    An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the device does not enforce any authentication. An adjacent attacker is able to use the network interface without proper access control.

    Published: 6 Oct 2019
    6.1
    Medium

    CVE-2019-17213

    Last Modified: 21 Nov 2024

    The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.

    Published: 6 Oct 2019
    7.5
    High

    CVE-2019-17214

    Last Modified: 21 Nov 2024

    The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.

    Published: 6 Oct 2019
    9.8
    Critical

    CVE-2019-17266

    Last Modified: 21 Nov 2024

    libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.

    Published: 6 Oct 2019
    6.5
    Medium

    CVE-2019-17402

    Last Modified: 21 Nov 2024

    Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

    Published: 6 Oct 2019
    5.5
    Medium

    CVE-2020-25663

    Last Modified: 21 Nov 2024

    A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue() was called. This could occur if an attacker is able to submit a malicious image file to be processed by ImageMagick and could lead to denial of service. It likely would not lead to anything further because the memory is used as pixel data and not e.g. a function pointer. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 6 Oct 2019
    5.5
    Medium

    CVE-2020-27756

    Last Modified: 21 Nov 2024

    In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefined behavior. This flaw can be triggered by a crafted input file processed by ImageMagick and could impact application availability. The patch uses multiplication in addition to the function `PerceptibleReciprocal()` in order to prevent such divide-by-zero conditions. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 6 Oct 2019
    9.8
    Critical

    CVE-2019-17206

    Last Modified: 21 Nov 2024

    Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.

    Published: 5 Oct 2019
    5.4
    Medium

    CVE-2019-17203

    Last Modified: 21 Nov 2024

    TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.

    Published: 5 Oct 2019
    5.4
    Medium

    CVE-2019-17204

    Last Modified: 21 Nov 2024

    TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.

    Published: 5 Oct 2019
    6.1
    Medium

    CVE-2019-17205

    Last Modified: 21 Nov 2024

    TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

    Published: 5 Oct 2019
    7.5
    High

    CVE-2019-17199

    Last Modified: 21 Nov 2024

    www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.

    Published: 5 Oct 2019
    9.8
    Critical

    CVE-2019-17197

    Last Modified: 21 Nov 2024

    OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.

    Published: 5 Oct 2019
    —
    Unknown

    CVE-2019-13145

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Oct 2019
    7.5
    High

    CVE-2019-17191

    Last Modified: 21 Nov 2024

    The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.

    Published: 5 Oct 2019
    9.8
    Critical

    CVE-2019-17192

    Last Modified: 21 Nov 2024

    The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs

    Published: 5 Oct 2019
    4.7
    Medium

    CVE-2019-19056

    Last Modified: 21 Nov 2024

    A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.

    Published: 5 Oct 2019