CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-15537

    Last Modified: 21 Nov 2024

    The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15535

    Last Modified: 21 Nov 2024

    Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.

    Published: 23 Aug 2019
    7.5
    High

    CVE-2019-11654

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.

    Published: 23 Aug 2019
    8
    High

    CVE-2019-1583

    Last Modified: 21 Nov 2024

    Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required for the payload to execute on the victim.

    Published: 23 Aug 2019
    7.2
    High

    CVE-2019-1582

    Last Modified: 21 Nov 2024

    Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-1581

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-1580

    Last Modified: 21 Nov 2024

    Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.

    Published: 23 Aug 2019
    5.5
    Medium

    CVE-2019-13013

    Last Modified: 21 Nov 2024

    Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.

    Published: 23 Aug 2019
    5.5
    Medium

    CVE-2019-13014

    Last Modified: 21 Nov 2024

    Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may therefore still be vulnerable after upgrading to 4.4.0. Version 4.4.1 fixes this issue by removing the operating system's copy during the upgrade.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-10750

    Last Modified: 21 Nov 2024

    deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-10751

    Last Modified: 21 Nov 2024

    All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15526

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15527

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15528

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15529

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15530

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.

    Published: 23 Aug 2019
    6.5
    Medium

    CVE-2019-15531

    Last Modified: 21 Nov 2024

    GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

    Published: 23 Aug 2019
    8.1
    High

    CVE-2019-15525

    Last Modified: 21 Nov 2024

    There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.

    Published: 23 Aug 2019
    5.3
    Medium

    CVE-2019-15520

    Last Modified: 21 Nov 2024

    comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.

    Published: 23 Aug 2019
    5.5
    Medium

    CVE-2019-15517

    Last Modified: 21 Nov 2024

    jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.

    Published: 23 Aug 2019
    5.3
    Medium

    CVE-2019-15518

    Last Modified: 21 Nov 2024

    Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15519

    Last Modified: 21 Nov 2024

    Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.

    Published: 23 Aug 2019
    7.5
    High

    CVE-2019-15516

    Last Modified: 21 Nov 2024

    Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.

    Published: 23 Aug 2019
    4.3
    Medium

    CVE-2019-8447

    Last Modified: 21 Nov 2024

    The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.

    Published: 23 Aug 2019
    5.3
    Medium

    CVE-2019-8446

    Last Modified: 21 Nov 2024

    The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

    Published: 23 Aug 2019
    5.3
    Medium

    CVE-2019-8445

    Last Modified: 21 Nov 2024

    Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.

    Published: 23 Aug 2019
    5.4
    Medium

    CVE-2019-8444

    Last Modified: 21 Nov 2024

    The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.

    Published: 23 Aug 2019
    4.3
    Medium

    CVE-2019-14999

    Last Modified: 21 Nov 2024

    The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-11589

    Last Modified: 21 Nov 2024

    The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.

    Published: 23 Aug 2019
    4.3
    Medium

    CVE-2019-11588

    Last Modified: 21 Nov 2024

    The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.

    Published: 23 Aug 2019
    6.5
    Medium

    CVE-2019-11587

    Last Modified: 21 Nov 2024

    Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).

    Published: 23 Aug 2019
    4.3
    Medium

    CVE-2019-11586

    Last Modified: 21 Nov 2024

    The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-11585

    Last Modified: 21 Nov 2024

    The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-11584

    Last Modified: 21 Nov 2024

    The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15482

    Last Modified: 21 Nov 2024

    selectize-plugin-a11y before 1.1.0 has XSS via the msg field.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15494

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.

    Published: 23 Aug 2019
    7.5
    High

    CVE-2019-15493

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15492

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15491

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15490

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15488

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15487

    Last Modified: 21 Nov 2024

    DfE School Experience before v16333-GA has XSS via a teacher training URL.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15486

    Last Modified: 21 Nov 2024

    django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15485

    Last Modified: 21 Nov 2024

    Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15484

    Last Modified: 21 Nov 2024

    Bolt before 3.6.10 has XSS via an image's alt or title field.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15483

    Last Modified: 21 Nov 2024

    Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15481

    Last Modified: 21 Nov 2024

    Kimai v2 before 1.1 has XSS via a timesheet description.

    Published: 23 Aug 2019
    5.4
    Medium

    CVE-2019-15480

    Last Modified: 21 Nov 2024

    Domoticz 4.10717 has XSS via item.Name.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15477

    Last Modified: 21 Nov 2024

    Jooby before 1.6.4 has XSS via the default error handler.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15476

    Last Modified: 21 Nov 2024

    Former before 4.2.1 has XSS via a checkbox value.

    Published: 23 Aug 2019