CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-15733

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.

    Published: 16 Sept 2019
    5.3
    Medium

    CVE-2019-15732

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

    Published: 16 Sept 2019
    5.3
    Medium

    CVE-2019-15731

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-15730

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-15728

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

    Published: 16 Sept 2019
    5.3
    Medium

    CVE-2019-15727

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.

    Published: 16 Sept 2019
    5.3
    Medium

    CVE-2019-15726

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-15725

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2019-15724

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

    Published: 16 Sept 2019
    5.3
    Medium

    CVE-2019-15723

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.

    Published: 16 Sept 2019
    7.2
    High

    CVE-2019-8371

    Last Modified: 21 Nov 2024

    OpenEMR v5.0.1-6 allows code execution.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-15722

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

    Published: 16 Sept 2019
    5.4
    Medium

    CVE-2019-15721

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10973

    Last Modified: 21 Nov 2024

    The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to BraftonAdminPage.php.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2016-10972

    Last Modified: 21 Nov 2024

    The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-0207

    Last Modified: 21 Nov 2024

    Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't filter the character `\`, so attacker can perform a path traversal attack to read any files on Windows platform.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2019-13140

    Last Modified: 21 Nov 2024

    Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" account to extract the 3DES key via JSON commands to ubus. The 3DES key is used to decrypt the provisioning file provided by Adamo Telecom on a public URL via cleartext HTTP.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2019-16366

    Last Modified: 21 Nov 2024

    In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.

    Published: 16 Sept 2019
    6.7
    Medium

    CVE-2019-11166

    Last Modified: 21 Nov 2024

    Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2019-15950

    Last Modified: 21 Nov 2024

    The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2019-0195

    Last Modified: 21 Nov 2024

    Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it downloaded. If the attacker found the file with the value of the tapestry.hmac-passphrase configuration symbol, most probably the webapp's AppModule class, the value of this symbol could be used to craft a Java deserialization attack, thus running malicious injected Java code. The vector would be the t:formdata parameter from the Form component.

    Published: 16 Sept 2019
    5.5
    Medium

    CVE-2019-16355

    Last Modified: 21 Nov 2024

    The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.

    Published: 16 Sept 2019
    4.7
    Medium

    CVE-2019-16354

    Last Modified: 21 Nov 2024

    The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2019-16353

    Last Modified: 21 Nov 2024

    Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic from a remote device, as demonstrated by an RX7i device.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2018-21015

    Last Modified: 21 Nov 2024

    AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2018-21016

    Last Modified: 21 Nov 2024

    audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2018-21017

    Last Modified: 21 Nov 2024

    GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.

    Published: 16 Sept 2019
    8.8
    High

    CVE-2019-16346

    Last Modified: 21 Nov 2024

    ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.

    Published: 16 Sept 2019
    8.8
    High

    CVE-2019-16347

    Last Modified: 21 Nov 2024

    ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2019-16348

    Last Modified: 21 Nov 2024

    marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.

    Published: 16 Sept 2019
    5.5
    Medium

    CVE-2019-16349

    Last Modified: 21 Nov 2024

    Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2019-16350

    Last Modified: 21 Nov 2024

    ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2019-16351

    Last Modified: 21 Nov 2024

    ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2019-16352

    Last Modified: 21 Nov 2024

    ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2016-10971

    Last Modified: 21 Nov 2024

    The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10970

    Last Modified: 21 Nov 2024

    The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10969

    Last Modified: 21 Nov 2024

    The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title.

    Published: 16 Sept 2019
    8.8
    High

    CVE-2016-10968

    Last Modified: 21 Nov 2024

    The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10967

    Last Modified: 21 Nov 2024

    The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2016-10966

    Last Modified: 21 Nov 2024

    The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2016-10965

    Last Modified: 21 Nov 2024

    The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10964

    Last Modified: 21 Nov 2024

    The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10963

    Last Modified: 21 Nov 2024

    The icegram plugin before 1.9.19 for WordPress has XSS.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2016-10962

    Last Modified: 21 Nov 2024

    The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10961

    Last Modified: 21 Nov 2024

    The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

    Published: 16 Sept 2019
    8.8
    High

    CVE-2016-10960

    Last Modified: 21 Nov 2024

    The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

    Published: 16 Sept 2019
    6.5
    Medium

    CVE-2016-10959

    Last Modified: 21 Nov 2024

    The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.

    Published: 16 Sept 2019
    7.5
    High

    CVE-2016-10958

    Last Modified: 21 Nov 2024

    The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.

    Published: 16 Sept 2019
    6.1
    Medium

    CVE-2016-10957

    Last Modified: 21 Nov 2024

    The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc parameter.

    Published: 16 Sept 2019
    9.8
    Critical

    CVE-2019-16264

    Last Modified: 21 Nov 2024

    In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database.

    Published: 16 Sept 2019