CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-12404

    Last Modified: 21 Nov 2024

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

    Published: 23 Sept 2019
    6.1
    Medium

    CVE-2019-10089

    Last Modified: 21 Nov 2024

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

    Published: 23 Sept 2019
    6.1
    Medium

    CVE-2019-10087

    Last Modified: 21 Nov 2024

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

    Published: 23 Sept 2019
    4.3
    Medium

    CVE-2019-16723

    Last Modified: 21 Nov 2024

    In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

    Published: 23 Sept 2019
    4.3
    Medium

    CVE-2019-16518

    Last Modified: 21 Nov 2024

    An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values.

    Published: 23 Sept 2019
    9.8
    Critical

    CVE-2019-3416

    Last Modified: 21 Nov 2024

    All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16719

    Last Modified: 21 Nov 2024

    WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16721

    Last Modified: 21 Nov 2024

    NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.

    Published: 23 Sept 2019
    9.8
    Critical

    CVE-2019-16722

    Last Modified: 21 Nov 2024

    ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

    Published: 23 Sept 2019
    7.5
    High

    CVE-2019-16720

    Last Modified: 21 Nov 2024

    ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

    Published: 23 Sept 2019
    7.8
    High

    CVE-2019-16718

    Last Modified: 21 Nov 2024

    In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to an insufficient fix for CVE-2019-14745 and improper handling of symbol names embedded in executables.

    Published: 23 Sept 2019
    —
    Unknown

    CVE-2019-16691

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Sept 2019
    8.8
    High

    CVE-2019-16706

    Last Modified: 21 Nov 2024

    kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.

    Published: 23 Sept 2019
    9.1
    Critical

    CVE-2019-16705

    Last Modified: 21 Nov 2024

    Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.

    Published: 23 Sept 2019
    4.8
    Medium

    CVE-2019-16704

    Last Modified: 21 Nov 2024

    admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.

    Published: 23 Sept 2019
    6.1
    Medium

    CVE-2019-16703

    Last Modified: 21 Nov 2024

    admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.

    Published: 23 Sept 2019
    9.8
    Critical

    CVE-2019-16702

    Last Modified: 21 Nov 2024

    Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-14886

    Last Modified: 21 Nov 2024

    A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could lead to user passwords being exposed.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16713

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.

    Published: 23 Sept 2019
    7.5
    High

    CVE-2019-16714

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16708

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16709

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16710

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16711

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.

    Published: 23 Sept 2019
    6.5
    Medium

    CVE-2019-16712

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.

    Published: 23 Sept 2019
    9.8
    Critical

    CVE-2019-16692

    Last Modified: 21 Nov 2024

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

    Published: 22 Sept 2019
    9.8
    Critical

    CVE-2019-16693

    Last Modified: 16 Apr 2025

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

    Published: 22 Sept 2019
    9.8
    Critical

    CVE-2019-16694

    Last Modified: 21 Nov 2024

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.

    Published: 22 Sept 2019
    9.8
    Critical

    CVE-2019-16695

    Last Modified: 21 Nov 2024

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.

    Published: 22 Sept 2019
    9.8
    Critical

    CVE-2019-16696

    Last Modified: 21 Nov 2024

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.

    Published: 22 Sept 2019
    9.8
    Critical

    CVE-2018-21018

    Last Modified: 21 Nov 2024

    Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

    Published: 22 Sept 2019
    7.5
    High

    CVE-2019-16884

    Last Modified: 21 Nov 2024

    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

    Published: 22 Sept 2019
    4.7
    Medium

    CVE-2019-16681

    Last Modified: 21 Nov 2024

    The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. The vendor states that the issue is not critical because it does not allow Elevation of Privilege, Sensitive Data Leakage, or any critical unauthorized activity from a malicious user. The vendor also states that a victim must first install a malicious APK to their application.

    Published: 21 Sept 2019
    4.9
    Medium

    CVE-2019-16679

    Last Modified: 21 Nov 2024

    Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.

    Published: 21 Sept 2019
    6.5
    Medium

    CVE-2019-16677

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.

    Published: 21 Sept 2019
    6.5
    Medium

    CVE-2019-16678

    Last Modified: 21 Nov 2024

    admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.

    Published: 21 Sept 2019
    5.3
    Medium

    CVE-2019-16669

    Last Modified: 21 Nov 2024

    The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.

    Published: 21 Sept 2019
    4.8
    Medium

    CVE-2019-16664

    Last Modified: 21 Nov 2024

    An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.

    Published: 21 Sept 2019
    6.1
    Medium

    CVE-2019-16665

    Last Modified: 21 Nov 2024

    An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC attribute of an EMBED element.

    Published: 21 Sept 2019
    7.5
    High

    CVE-2019-16655

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.

    Published: 21 Sept 2019
    9.8
    Critical

    CVE-2019-16656

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.

    Published: 21 Sept 2019
    6.1
    Medium

    CVE-2019-16657

    Last Modified: 21 Nov 2024

    TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.

    Published: 21 Sept 2019
    8.8
    High

    CVE-2019-16658

    Last Modified: 21 Nov 2024

    TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.

    Published: 21 Sept 2019
    8.8
    High

    CVE-2019-16659

    Last Modified: 21 Nov 2024

    TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.

    Published: 21 Sept 2019
    8.8
    High

    CVE-2019-16660

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.

    Published: 21 Sept 2019
    5.4
    Medium

    CVE-2019-16661

    Last Modified: 21 Nov 2024

    Ogma CMS 0.5 has XSS via creation of a new blog.

    Published: 21 Sept 2019
    10
    Critical

    CVE-2019-16649

    Last Modified: 21 Nov 2024

    On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC.

    Published: 21 Sept 2019
    10
    Critical

    CVE-2019-16650

    Last Modified: 21 Nov 2024

    On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC.

    Published: 21 Sept 2019
    6.1
    Medium

    CVE-2019-16935

    Last Modified: 21 Nov 2024

    The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

    Published: 21 Sept 2019
    6.7
    Medium

    CVE-2019-6145

    Last Modified: 21 Nov 2024

    Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this vulnerability and for reporting it to us.

    Published: 20 Sept 2019