CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2019-16173

    Last Modified: 21 Nov 2024

    LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-11605

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.

    Published: 9 Sept 2019
    7.2
    High

    CVE-2019-5473

    Last Modified: 21 Nov 2024

    An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-5471

    Last Modified: 21 Nov 2024

    An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2019-5467

    Last Modified: 21 Nov 2024

    An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-5463

    Last Modified: 21 Nov 2024

    An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

    Published: 9 Sept 2019
    3.5
    Low

    CVE-2019-5461

    Last Modified: 21 Nov 2024

    An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-5483

    Last Modified: 21 Nov 2024

    Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-12405

    Last Modified: 21 Nov 2024

    Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-16164

    Last Modified: 21 Nov 2024

    MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-16165

    Last Modified: 21 Nov 2024

    GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-16166

    Last Modified: 21 Nov 2024

    GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16159

    Last Modified: 21 Nov 2024

    BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes a four-byte overflow to occur while processing the message, where two of the overflow bytes are attacker-controlled and two are fixed.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-10670

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, this is particularly ineffective when returning user supplied input in an HTML or a JavaScript context, resulting in unsafe data being injected into these contexts, leading to attacker controlled JavaScript executing in the browser. One example of this is the string parameter in html/pages/inventory.inc.php.

    Published: 9 Sept 2019
    8.1
    High

    CVE-2019-12465

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-12464

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial filename in the report parameter, to cause local file inclusion resulting in code execution.

    Published: 9 Sept 2019
    8.8
    High

    CVE-2019-12463

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php and html/graph-realtime.php scripts. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, disclosing file content, denial of service, or writing arbitrary files. NOTE: relative to CVE-2019-10665, this requires authentication and the pathnames differ.

    Published: 9 Sept 2019
    8.8
    High

    CVE-2019-10671

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php sort parameter.

    Published: 9 Sept 2019
    9.1
    Critical

    CVE-2019-10668

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.

    Published: 9 Sept 2019
    5.3
    Medium

    CVE-2019-10667

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.

    Published: 9 Sept 2019
    8.1
    High

    CVE-2019-10666

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attacker can leverage this to execute PHP code from the included file. Exploitation of these scripts is made difficult by additional text being appended (typically .inc.php), which means an attacker would need to be able to control both a filename and its content on the server. However, exploitation can be achieved as demonstrated by the csv.php?report=../ substring.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-10665

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php script. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, file content, denial of service, or writing arbitrary files.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-15895

    Last Modified: 21 Nov 2024

    search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-15639

    Last Modified: 21 Nov 2024

    main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

    Published: 9 Sept 2019
    7.2
    High

    CVE-2019-10669

    Last Modified: 21 Nov 2024

    An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does not escape a number of command line syntax characters such as ` (backtick), allowing an attacker to inject commands into the variable $rrd_cmd, which gets executed via passthru().

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16148

    Last Modified: 21 Nov 2024

    Sakai through 12.6 allows XSS via a chat user name.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16114

    Last Modified: 21 Nov 2024

    In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

    Published: 9 Sept 2019
    4.8
    Medium

    CVE-2019-16146

    Last Modified: 21 Nov 2024

    Gophish through 0.8.0 allows XSS via a username.

    Published: 9 Sept 2019
    5.4
    Medium

    CVE-2018-21014

    Last Modified: 21 Nov 2024

    The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2018-21013

    Last Modified: 21 Nov 2024

    The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2018-21012

    Last Modified: 21 Nov 2024

    The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2018-21011

    Last Modified: 21 Nov 2024

    The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16144

    Last Modified: 21 Nov 2024

    An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16143

    Last Modified: 21 Nov 2024

    An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16142

    Last Modified: 21 Nov 2024

    An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16141

    Last Modified: 21 Nov 2024

    An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16139

    Last Modified: 21 Nov 2024

    An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16138

    Last Modified: 21 Nov 2024

    An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len is called on an uninitialized vector, leading to a use-after-free and arbitrary code execution.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16137

    Last Modified: 21 Nov 2024

    An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16130

    Last Modified: 21 Nov 2024

    YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.

    Published: 9 Sept 2019
    8.8
    High

    CVE-2019-16131

    Last Modified: 21 Nov 2024

    framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-16132

    Last Modified: 21 Nov 2024

    An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.

    Published: 9 Sept 2019
    6.5
    Medium

    CVE-2019-16133

    Last Modified: 21 Nov 2024

    An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16124

    Last Modified: 21 Nov 2024

    In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16125

    Last Modified: 21 Nov 2024

    In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16126

    Last Modified: 21 Nov 2024

    Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-16123

    Last Modified: 21 Nov 2024

    In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.

    Published: 9 Sept 2019
    4.7
    Medium

    CVE-2019-16230

    Last Modified: 28 May 2026

    drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening during device initialization, which for a graphics card occurs during boot. It is not attacker controllable and OOM at that time is highly unlikely

    Published: 9 Sept 2019
    4.1
    Medium

    CVE-2019-16229

    Last Modified: 21 Nov 2024

    drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id

    Published: 9 Sept 2019
    4.1
    Medium

    CVE-2019-16233

    Last Modified: 21 Nov 2024

    drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

    Published: 9 Sept 2019