CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-12685

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12684

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12683

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12682

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12681

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12680

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12679

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input validation. An attacker could exploit these vulnerabilities by sending crafted SQL queries to an affected device. A successful exploit could allow the attacker to view information that they are not authorized to view, make changes to the system that they are not authorized to make, and execute commands within the underlying operating system that may affect the availability of the device.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-12678

    Last Modified: 11 Aug 2026

    A vulnerability in the Session Initiation Protocol (SIP) inspection module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper parsing of SIP messages. An attacker could exploit this vulnerability by sending a malicious SIP packet through an affected device. A successful exploit could allow the attacker to trigger an integer underflow, causing the software to try to read unmapped memory and resulting in a crash.

    Published: 2 Oct 2019
    6.5
    Medium

    CVE-2019-12677

    Last Modified: 21 Nov 2024

    A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device. The vulnerability is due to incorrect handling of Base64-encoded strings. An attacker could exploit this vulnerability by opening many SSL VPN sessions to an affected device. The attacker would need to have valid user credentials on the affected device to exploit this vulnerability. A successful exploit could allow the attacker to overwrite a special system memory location, which will eventually result in memory allocation errors for new SSL/TLS sessions to the device, preventing successful establishment of these sessions. A reload of the device is required to recover from this condition. Established SSL/TLS connections to the device and SSL/TLS connections through the device are not affected. Note: Although this vulnerability is in the SSL VPN feature, successful exploitation of this vulnerability would affect all new SSL/TLS sessions to the device, including management sessions.

    Published: 2 Oct 2019
    7.4
    High

    CVE-2019-12676

    Last Modified: 11 Aug 2026

    A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software improperly parses certain options in OSPF link-state advertisement (LSA) type 11 packets. An attacker could exploit this vulnerability by sending a crafted LSA type 11 OSPF packet to an affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition for client traffic that is traversing the device.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-12675

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.

    Published: 2 Oct 2019
    8.2
    High

    CVE-2019-12674

    Last Modified: 11 Aug 2026

    Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insufficient protections on the underlying filesystem. An attacker could exploit these vulnerabilities by modifying critical files on the underlying filesystem. A successful exploit could allow the attacker to execute commands with root privileges within the host namespace. This could allow the attacker to impact other running FTD instances.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-12673

    Last Modified: 11 Aug 2026

    A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of FTP data. An attacker could exploit this vulnerability by sending malicious FTP traffic through an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.

    Published: 2 Oct 2019
    5.3
    Medium

    CVE-2019-12156

    Last Modified: 21 Nov 2024

    Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-12157

    Last Modified: 21 Nov 2024

    In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-12736

    Last Modified: 21 Nov 2024

    JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

    Published: 2 Oct 2019
    5.3
    Medium

    CVE-2019-12737

    Last Modified: 21 Nov 2024

    UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-13957

    Last Modified: 21 Nov 2024

    In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.

    Published: 2 Oct 2019
    4.3
    Medium

    CVE-2019-14956

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-14958

    Last Modified: 21 Nov 2024

    JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.

    Published: 2 Oct 2019
    5.9
    Medium

    CVE-2019-14959

    Last Modified: 21 Nov 2024

    JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.

    Published: 2 Oct 2019
    7.2
    High

    CVE-2019-15036

    Last Modified: 21 Nov 2024

    An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-15037

    Last Modified: 21 Nov 2024

    An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-15040

    Last Modified: 21 Nov 2024

    JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-16171

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-12631

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-12630

    Last Modified: 21 Nov 2024

    A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser.

    Published: 2 Oct 2019
    7.3
    High

    CVE-2019-16407

    Last Modified: 21 Nov 2024

    JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-8462

    Last Modified: 21 Nov 2024

    In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-13658

    Last Modified: 21 Nov 2024

    CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

    Published: 2 Oct 2019
    8.8
    High

    CVE-2019-5031

    Last Modified: 21 Nov 2024

    An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory condition which isn't handled properly, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-13343

    Last Modified: 21 Nov 2024

    Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsible for this vulnerability. It does not properly sanitize user input on the theme t parameter before reusing it in a path. This path is then used without validation to fetch a file and return its raw content to the user via the /wl?t=../../...&h= substring followed by a filename.

    Published: 2 Oct 2019
    4.3
    Medium

    CVE-2019-16116

    Last Modified: 21 Nov 2024

    EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-13025

    Last Modified: 21 Nov 2024

    Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be executed on the device, to an backend API endpoint of the cable modem.

    Published: 2 Oct 2019
    5.3
    Medium

    CVE-2019-4549

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 165951.

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-4542

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.

    Published: 2 Oct 2019
    7.1
    High

    CVE-2019-4539

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.

    Published: 2 Oct 2019
    8.2
    High

    CVE-2019-4538

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 165660.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2019-4520

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 165178.

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-17091

    Last Modified: 21 Nov 2024

    faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

    Published: 2 Oct 2019
    7.8
    High

    CVE-2019-17080

    Last Modified: 21 Nov 2024

    mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-14454

    Last Modified: 21 Nov 2024

    SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2019-13335

    Last Modified: 21 Nov 2024

    SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14465

    Last Modified: 17 Dec 2025

    The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14468

    Last Modified: 3 Dec 2025

    The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14462

    Last Modified: 3 Dec 2025

    The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14461

    Last Modified: 3 Dec 2025

    The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

    Published: 2 Oct 2019
    1.6
    Low

    CVE-2019-15166

    Last Modified: 3 Dec 2025

    lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16452

    Last Modified: 3 Dec 2025

    The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16451

    Last Modified: 3 Dec 2025

    The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

    Published: 2 Oct 2019