CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-13659

    Last Modified: 21 Nov 2024

    IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 10 Sept 2019
    4.3
    Medium

    CVE-2019-13661

    Last Modified: 21 Nov 2024

    UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.

    Published: 10 Sept 2019
    4.3
    Medium

    CVE-2019-13667

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 10 Sept 2019
    7.4
    High

    CVE-2019-13668

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 10 Sept 2019
    7.4
    High

    CVE-2019-13673

    Last Modified: 21 Nov 2024

    Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 10 Sept 2019
    4.3
    Medium

    CVE-2019-13691

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 10 Sept 2019
    6.5
    Medium

    CVE-2019-10253

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-15297

    Last Modified: 21 Nov 2024

    res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sending a declined stream in a response to a T.38 re-invite initiated by Asterisk. The crash occurs because of a NULL session media object dereference.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16145

    Last Modified: 21 Nov 2024

    The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16147

    Last Modified: 21 Nov 2024

    Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.

    Published: 9 Sept 2019
    8.8
    High

    CVE-2019-16174

    Last Modified: 21 Nov 2024

    An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-16175

    Last Modified: 21 Nov 2024

    A clickjacking vulnerability was found in Limesurvey before 3.17.14.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-16176

    Last Modified: 21 Nov 2024

    A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the path to the application in the filesystem.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16177

    Last Modified: 21 Nov 2024

    In Limesurvey before 3.17.14, the entire database is exposed through browser caching.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16192

    Last Modified: 21 Nov 2024

    upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file in a ZIP archive.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-16178

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-16179

    Last Modified: 21 Nov 2024

    Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-16180

    Last Modified: 21 Nov 2024

    Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.

    Published: 9 Sept 2019
    2.7
    Low

    CVE-2019-16181

    Last Modified: 21 Nov 2024

    In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16182

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.

    Published: 9 Sept 2019
    2.7
    Low

    CVE-2019-16183

    Last Modified: 21 Nov 2024

    In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16184

    Last Modified: 21 Nov 2024

    A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.

    Published: 9 Sept 2019
    7.2
    High

    CVE-2019-16185

    Last Modified: 21 Nov 2024

    In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-6791

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 3 of 3). When a project with visibility more permissive than the target group is imported, it will retain its prior visibility.

    Published: 9 Sept 2019
    7.2
    High

    CVE-2019-16186

    Last Modified: 21 Nov 2024

    In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16187

    Last Modified: 21 Nov 2024

    Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.

    Published: 9 Sept 2019
    3.7
    Low

    CVE-2019-7176

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-6997

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-6996

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16190

    Last Modified: 21 Nov 2024

    SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-6995

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-6960

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-6795

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Insufficient Visual Distinction of Homoglyphs Presented to a User. IDN homographs and RTLO characters are rendered to unicode, which could be used for social engineering.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-6794

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

    Published: 9 Sept 2019
    7
    High

    CVE-2019-6793

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-6792

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-6789

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6). In some cases, users without project permissions will receive emails after a project move. For private projects, this will disclose the new project namespace to an unauthorized user.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-6788

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-6786

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-6785

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Denial of Service. Inputting an overly long string into a Markdown field could cause a denial of service.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-6784

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 1 of 2). Markdown fields contain a lack of input validation and output encoding when processing KaTeX that results in a persistent XSS.

    Published: 9 Sept 2019
    8.8
    High

    CVE-2019-6783

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. GitLab Pages contains a directory traversal vulnerability that could lead to remote command execution.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-6782

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 1 of 6). An authorization issue allows the contributed project information of a private profile to be viewed.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-11549

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-11548

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-11547

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-11546

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-11545

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.

    Published: 9 Sept 2019
    4.3
    Medium

    CVE-2019-11544

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-16172

    Last Modified: 21 Nov 2024

    LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

    Published: 9 Sept 2019