CVE-2019-15537
Last Modified: 21 Nov 2024The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2019-15535
Last Modified: 21 Nov 2024Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
CVE-2019-11654
Last Modified: 21 Nov 2024Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files.
CVE-2019-1583
Last Modified: 21 Nov 2024Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required for the payload to execute on the victim.
CVE-2019-1582
Last Modified: 21 Nov 2024Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause arbitrary memory corruption by rekeying the current client interactive session.
CVE-2019-1581
Last Modified: 21 Nov 2024A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25; 8.0 versions prior to 8.0.19-h1, 8.0.20; 8.1 versions prior to 8.1.9-h4, 8.1.10; 9.0 versions prior to 9.0.3-h3, 9.0.4.
CVE-2019-1580
Last Modified: 21 Nov 2024Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.
CVE-2019-13013
Last Modified: 21 Nov 2024Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.
CVE-2019-13014
Last Modified: 21 Nov 2024Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may therefore still be vulnerable after upgrading to 4.4.0. Version 4.4.1 fixes this issue by removing the operating system's copy during the upgrade.
CVE-2019-10750
Last Modified: 21 Nov 2024deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
CVE-2019-10751
Last Modified: 21 Nov 2024All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.
CVE-2019-15526
Last Modified: 21 Nov 2024An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
CVE-2019-15527
Last Modified: 21 Nov 2024An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.
CVE-2019-15528
Last Modified: 21 Nov 2024An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
CVE-2019-15529
Last Modified: 21 Nov 2024An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
CVE-2019-15530
Last Modified: 21 Nov 2024An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
CVE-2019-15531
Last Modified: 21 Nov 2024GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
CVE-2019-15525
Last Modified: 21 Nov 2024There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
CVE-2019-15520
Last Modified: 21 Nov 2024comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
CVE-2019-15517
Last Modified: 21 Nov 2024jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
CVE-2019-15518
Last Modified: 21 Nov 2024Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
CVE-2019-15519
Last Modified: 21 Nov 2024Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
CVE-2019-15516
Last Modified: 21 Nov 2024Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
CVE-2019-8447
Last Modified: 21 Nov 2024The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
CVE-2019-8446
Last Modified: 21 Nov 2024The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
CVE-2019-8445
Last Modified: 21 Nov 2024Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
CVE-2019-8444
Last Modified: 21 Nov 2024The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification.
CVE-2019-14999
Last Modified: 21 Nov 2024The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
CVE-2019-11589
Last Modified: 21 Nov 2024The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
CVE-2019-11588
Last Modified: 21 Nov 2024The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
CVE-2019-11587
Last Modified: 21 Nov 2024Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
CVE-2019-11586
Last Modified: 21 Nov 2024The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.
CVE-2019-11585
Last Modified: 21 Nov 2024The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
CVE-2019-11584
Last Modified: 21 Nov 2024The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
CVE-2019-15482
Last Modified: 21 Nov 2024selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-15494
Last Modified: 21 Nov 2024openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
CVE-2019-15493
Last Modified: 21 Nov 2024openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
CVE-2019-15492
Last Modified: 21 Nov 2024openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15491
Last Modified: 21 Nov 2024openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVE-2019-15490
Last Modified: 21 Nov 2024openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
CVE-2019-15488
Last Modified: 21 Nov 2024Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
CVE-2019-15487
Last Modified: 21 Nov 2024DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15486
Last Modified: 21 Nov 2024django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
CVE-2019-15485
Last Modified: 21 Nov 2024Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
CVE-2019-15484
Last Modified: 21 Nov 2024Bolt before 3.6.10 has XSS via an image's alt or title field.
CVE-2019-15483
Last Modified: 21 Nov 2024Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
CVE-2019-15481
Last Modified: 21 Nov 2024Kimai v2 before 1.1 has XSS via a timesheet description.
CVE-2019-15480
Last Modified: 21 Nov 2024Domoticz 4.10717 has XSS via item.Name.
CVE-2019-15477
Last Modified: 21 Nov 2024Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-15476
Last Modified: 21 Nov 2024Former before 4.2.1 has XSS via a checkbox value.
