CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-5992

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 12 Sept 2019
    8.8
    High

    CVE-2019-5996

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 12 Sept 2019
    9.8
    Critical

    CVE-2019-6005

    Last Modified: 21 Nov 2024

    Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as installing arbitrary software or changing the device settings via Android Debug Bridge port 5555/TCP.

    Published: 12 Sept 2019
    8.8
    High

    CVE-2019-6007

    Last Modified: 21 Nov 2024

    Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.

    Published: 12 Sept 2019
    6.1
    Medium

    CVE-2019-16238

    Last Modified: 21 Nov 2024

    Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.

    Published: 12 Sept 2019
    8.1
    High

    CVE-2019-3638

    Last Modified: 21 Nov 2024

    Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.8.2.13 allows remote attackers to collect sensitive information or execute commands with the MWG administrator's credentials via tricking the administrator to click on a carefully constructed malicious link.

    Published: 12 Sept 2019
    9.1
    Critical

    CVE-2019-16261

    Last Modified: 21 Mar 2025

    Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.

    Published: 12 Sept 2019
    3.1
    Low

    CVE-2019-10397

    Last Modified: 21 Nov 2024

    Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 12 Sept 2019
    5.4
    Medium

    CVE-2019-10395

    Last Modified: 21 Nov 2024

    Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.

    Published: 12 Sept 2019
    5.4
    Medium

    CVE-2019-10396

    Last Modified: 21 Nov 2024

    Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions.

    Published: 12 Sept 2019
    5.5
    Medium

    CVE-2019-10398

    Last Modified: 21 Nov 2024

    Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 12 Sept 2019
    9.8
    Critical

    CVE-2019-16256

    Last Modified: 12 Nov 2025

    Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

    Published: 12 Sept 2019
    9.8
    Critical

    CVE-2019-16257

    Last Modified: 21 Nov 2024

    Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

    Published: 12 Sept 2019
    4.2
    Medium

    CVE-2019-10399

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions in increment and decrement expressions allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 12 Sept 2019
    8.8
    High

    CVE-2019-10392

    Last Modified: 21 Nov 2024

    Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.

    Published: 12 Sept 2019
    4.2
    Medium

    CVE-2019-10400

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 12 Sept 2019
    4.2
    Medium

    CVE-2019-10393

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 12 Sept 2019
    4.2
    Medium

    CVE-2019-10394

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 12 Sept 2019
    7.5
    High

    CVE-2019-16250

    Last Modified: 21 Nov 2024

    includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-16248

    Last Modified: 21 Nov 2024

    The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a potentially misleading UI indication that a sender can remove a recipient's copy of a previously sent image (analogous to supported functionality in which a sender can remove a recipient's copy of a previously sent message).

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1303

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1278.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-1293

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1290

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.

    Published: 11 Sept 2019
    4.9
    Medium

    CVE-2019-1292

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-1300

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1298.

    Published: 11 Sept 2019
    5.4
    Medium

    CVE-2019-1305

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1291

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1290.

    Published: 11 Sept 2019
    4.6
    Medium

    CVE-2019-1294

    Last Modified: 21 Nov 2024

    A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1295

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1296

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-1298

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1138, CVE-2019-1217, CVE-2019-1237, CVE-2019-1300.

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-1299

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1302

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-1306

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-1289

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-1297

    Last Modified: 29 Oct 2025

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1287

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles objects in memory, aka 'Windows Network Connectivity Assistant Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-1270

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1280

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-1282

    Last Modified: 21 Nov 2024

    An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.

    Published: 11 Sept 2019
    5.5
    Medium

    CVE-2019-1283

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-1286

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1268

    Last Modified: 21 Nov 2024

    An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1269

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1272.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1271

    Last Modified: 21 Nov 2024

    An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    5.4
    Medium

    CVE-2019-1273

    Last Modified: 21 Nov 2024

    A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1277

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed, aka 'Windows Audio Service Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1284

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1285

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-1278

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303.

    Published: 11 Sept 2019