CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-5054

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-13540

    Last Modified: 21 Nov 2024

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-13536

    Last Modified: 21 Nov 2024

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-13544

    Last Modified: 21 Nov 2024

    Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files, which may allow remote code execution.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-10074

    Last Modified: 21 Nov 2024

    An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-15302

    Last Modified: 21 Nov 2024

    The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-10073

    Last Modified: 21 Nov 2024

    The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-0189

    Last Modified: 21 Nov 2024

    The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2018-17200

    Last Modified: 21 Nov 2024

    The Apache OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. This service takes the `serviceContent` parameter in the request and deserializes it using XStream. This `XStream` instance is slightly guarded by disabling the creation of `ProcessBuilder`. However, this can be easily bypassed (and in multiple ways). Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16 r1850017+1850019

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-11769

    Last Modified: 21 Nov 2024

    An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these credentials are processed in Teamviewer.exe, which allows any application running in the same non-administrative user context to intercept them in cleartext within process memory. By using this technique, a local attacker is able to obtain administrative credentials in order to elevate privileges. This vulnerability can be exploited by injecting code into Teamviewer.exe which intercepts calls to GetWindowTextW and logs the processed credentials.

    Published: 11 Sept 2019
    8.8
    High

    CVE-2019-3763

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure vulnerability. The Office 365 user password may get logged in a plain text format in the Office 365 connector debug log file. An authenticated malicious local user with access to the debug logs may obtain the exposed password to use in further attacks.

    Published: 11 Sept 2019
    5.4
    Medium

    CVE-2019-3761

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-site scripting vulnerability in the Access Request module. A remote authenticated malicious user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the stored malicious code would gets executed by the web browser in the context of the vulnerable web application.

    Published: 11 Sept 2019
    6.4
    Medium

    CVE-2019-3760

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a SQL Injection vulnerability in Workflow Architect. A remote authenticated malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the data by supplying specially crafted input data to the affected application.

    Published: 11 Sept 2019
    6.4
    Medium

    CVE-2019-3759

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-16235

    Last Modified: 21 Nov 2024

    Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-16236

    Last Modified: 21 Nov 2024

    Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-16237

    Last Modified: 21 Nov 2024

    Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.

    Published: 11 Sept 2019
    5.3
    Medium

    CVE-2019-14936

    Last Modified: 21 Nov 2024

    Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).

    Published: 11 Sept 2019
    4.9
    Medium

    CVE-2019-9488

    Last Modified: 21 Nov 2024

    Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).

    Published: 11 Sept 2019
    7.8
    High

    CVE-2019-16098

    Last Modified: 21 Nov 2024

    The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-16224

    Last Modified: 21 Nov 2024

    An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy destination, leading to an invalid write operation. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-16225

    Last Modified: 21 Nov 2024

    An issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_pg[mc->top], leading to an invalid write operation. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-16226

    Last Modified: 21 Nov 2024

    An issue was discovered in py-lmdb 0.97. mdb_node_del does not validate a memmove in the case of an unexpected node->mn_hi, leading to an invalid write operation. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-16227

    Last Modified: 21 Nov 2024

    An issue was discovered in py-lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invalid write operation within mdb_xcursor_init1. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-16228

    Last Modified: 21 Nov 2024

    An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a zero value for a certain size field. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-3644

    Last Modified: 21 Nov 2024

    McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially leading to a denial of service. This affects the scanning proxies.

    Published: 11 Sept 2019
    5.3
    Medium

    CVE-2019-3643

    Last Modified: 21 Nov 2024

    McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially leading to a denial of service. This affects the scanning proxies.

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-8451

    Last Modified: 21 Nov 2024

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

    Published: 11 Sept 2019
    4.8
    Medium

    CVE-2019-8450

    Last Modified: 21 Nov 2024

    Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 allow remote attackers who have permission to manage custom fields to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a custom field.

    Published: 11 Sept 2019
    5.3
    Medium

    CVE-2019-8449

    Last Modified: 21 Nov 2024

    The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability.

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-14998

    Last Modified: 21 Nov 2024

    The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.

    Published: 11 Sept 2019
    4.3
    Medium

    CVE-2019-14997

    Last Modified: 21 Nov 2024

    The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with caching or a CDN.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-14996

    Last Modified: 21 Nov 2024

    The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

    Published: 11 Sept 2019
    5.3
    Medium

    CVE-2019-14995

    Last Modified: 21 Nov 2024

    The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16217

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16219

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 allows XSS in shortcode previews.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16221

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 allows reflected XSS in the dashboard.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16222

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.

    Published: 11 Sept 2019
    5.4
    Medium

    CVE-2019-16223

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 allows XSS in post previews by authenticated users.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16220

    Last Modified: 21 Nov 2024

    In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.

    Published: 11 Sept 2019
    6.1
    Medium

    CVE-2019-16218

    Last Modified: 21 Nov 2024

    WordPress before 5.2.3 allows XSS in stored comments.

    Published: 11 Sept 2019
    5.4
    Medium

    CVE-2019-16193

    Last Modified: 21 Nov 2024

    In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-14724

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination of a victim's account via an attacker account.

    Published: 11 Sept 2019
    4.3
    Medium

    CVE-2019-14725

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail usage value of a victim account via an attacker account.

    Published: 11 Sept 2019
    5.7
    Medium

    CVE-2019-16214

    Last Modified: 21 Nov 2024

    Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character for a comment. For example, a Move module author can enter the // sequence (which introduces a single-line comment), followed by very brief comment text, the \r character, and code that has security-critical functionality. In many popular environments, this code is displayed on a separate line, and thus a reader may infer that the code is executed. However, the code is NOT executed, because language/compiler/ir_to_bytecode/src/parser.rs allows the comment to continue after the \r character.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-13473

    Last Modified: 21 Nov 2024

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.

    Published: 11 Sept 2019
    7.5
    High

    CVE-2019-11777

    Last Modified: 21 Nov 2024

    In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with incorrect information.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-5481

    Last Modified: 16 Apr 2026

    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

    Published: 11 Sept 2019
    6.5
    Medium

    CVE-2019-16275

    Last Modified: 21 Nov 2024

    hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.

    Published: 11 Sept 2019
    9.8
    Critical

    CVE-2019-16746

    Last Modified: 21 Nov 2024

    An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.

    Published: 11 Sept 2019