CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-14684

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-15082

    Last Modified: 21 Nov 2024

    The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-15233

    Last Modified: 21 Nov 2024

    The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.

    Published: 20 Aug 2019
    5.3
    Medium

    CVE-2019-14430

    Last Modified: 21 Nov 2024

    plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

    Published: 20 Aug 2019
    3.3
    Low

    CVE-2019-11806

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.1 and earlier has Insecure Permissions.

    Published: 20 Aug 2019
    5.4
    Medium

    CVE-2019-11522

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.0 to 7.10.2 allows XSS.

    Published: 20 Aug 2019
    8.1
    High

    CVE-2019-11521

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.1 allows Content Spoofing.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2018-20975

    Last Modified: 21 Nov 2024

    Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.

    Published: 20 Aug 2019
    7
    High

    CVE-2019-12889

    Last Modified: 21 Nov 2024

    An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer from the local network / WAN and connect it to an internet facing access point / network. At that point, the attacker can execute the password-reset functionality, which will expose a web browser. Browsing to a site that calls local Windows system functions (e.g., file upload) will expose the local file system. From there an attacker can launch a privileged command shell.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-15227

    Last Modified: 21 Nov 2024

    FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.

    Published: 20 Aug 2019
    7.4
    High

    CVE-2019-15237

    Last Modified: 21 Nov 2024

    Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.

    Published: 20 Aug 2019
    7.8
    High

    CVE-2019-15239

    Last Modified: 21 Nov 2024

    In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability that was potentially more severe than the issue that was intended to be fixed by backporting. Specifically, by adding to a write queue between disconnection and re-connection, a local attacker can trigger multiple use-after-free conditions. This can result in a kernel crash, or potentially in privilege escalation. NOTE: this affects (for example) Linux distributions that use 4.9.x longterm kernels before 4.9.190 or 4.14.x longterm kernels before 4.14.139.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-15026

    Last Modified: 21 Nov 2024

    memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2016-10893

    Last Modified: 21 Nov 2024

    The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-15232

    Last Modified: 21 Nov 2024

    Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.

    Published: 19 Aug 2019
    —
    Unknown

    CVE-2019-15231

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of CVE-2019-15107. Notes: All CVE users should reference CVE-2019-15107 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Aug 2019
    8.8
    High

    CVE-2019-15229

    Last Modified: 21 Nov 2024

    FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

    Published: 19 Aug 2019
    5.4
    Medium

    CVE-2019-15228

    Last Modified: 21 Nov 2024

    FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.

    Published: 19 Aug 2019
    7.6
    High

    CVE-2019-0173

    Last Modified: 21 Nov 2024

    Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attacker to potentially enable disclosure of information via network access.

    Published: 19 Aug 2019
    6.7
    Medium

    CVE-2019-11140

    Last Modified: 21 Nov 2024

    Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 19 Aug 2019
    6.7
    Medium

    CVE-2019-11143

    Last Modified: 21 Nov 2024

    Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-11146

    Last Modified: 21 Nov 2024

    Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-11145

    Last Modified: 21 Nov 2024

    Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-11148

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-11163

    Last Modified: 21 Nov 2024

    Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows before version 6.1.0731 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-11162

    Last Modified: 21 Nov 2024

    Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before version 2.4.0.04733 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

    Published: 19 Aug 2019
    5.3
    Medium

    CVE-2019-6178

    Last Modified: 21 Nov 2024

    An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.

    Published: 19 Aug 2019
    6.8
    Medium

    CVE-2019-6171

    Last Modified: 21 Nov 2024

    A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-6165

    Last Modified: 21 Nov 2024

    A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Night light feature introduced in Windows 10 Build 1703 provides similar features.

    Published: 19 Aug 2019
    6.1
    Medium

    CVE-2019-6159

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the user's web browser when IMM log records containing the JavaScript code are viewed. The JavaScript code is not executed on IMM itself. The later IMM2 (IMM v2) is not affected.

    Published: 19 Aug 2019
    5.4
    Medium

    CVE-2019-11276

    Last Modified: 21 Nov 2024

    Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requests via unsecured http. An adjacent unauthenticated user could eavesdrop on the network traffic and gain access to the unencrypted token allowing the attacker to read the type of access a user has over an app. They may also modify the logging level, potentially leading to lost information that would otherwise have been logged.

    Published: 19 Aug 2019
    7.8
    High

    CVE-2019-5631

    Last Modified: 21 Nov 2024

    The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating system) can elevate their privileges with this vulnerability to the privilege level of InsightAppSec (usually, SYSTEM). This issue affects version 2019.06.24 and prior versions of the product.

    Published: 19 Aug 2019
    7.5
    High

    CVE-2019-15160

    Last Modified: 21 Nov 2024

    The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (resource consumption) via an XML entity expansion attack with an inline DTD.

    Published: 19 Aug 2019
    8.8
    High

    CVE-2019-15150

    Last Modified: 21 Nov 2024

    In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15213

    Last Modified: 28 May 2026

    An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15217

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15219

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.

    Published: 19 Aug 2019
    9.8
    Critical

    CVE-2019-15224

    Last Modified: 21 Nov 2024

    The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

    Published: 19 Aug 2019
    6.3
    Medium

    CVE-2019-10225

    Last Modified: 21 Nov 2024

    A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.

    Published: 19 Aug 2019
    6.7
    Medium

    CVE-2019-20908

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15211

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15212

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.

    Published: 19 Aug 2019
    6.4
    Medium

    CVE-2019-15214

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.0.10. There is a use-after-free in the sound subsystem because card disconnection causes certain data structures to be deleted too early. This is related to sound/core/init.c and sound/core/info.c.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15218

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15215

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c driver.

    Published: 19 Aug 2019
    4.6
    Medium

    CVE-2019-15216

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.

    Published: 19 Aug 2019
    7.5
    High

    CVE-2019-15225

    Last Modified: 21 Nov 2024

    In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to result in a denial of service (memory consumption). This is a related issue to CVE-2019-14993.

    Published: 19 Aug 2019
    4.2
    Medium

    CVE-2020-15719

    Last Modified: 21 Nov 2024

    libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

    Published: 19 Aug 2019
    9.8
    Critical

    CVE-2019-15151

    Last Modified: 21 Nov 2024

    AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

    Published: 18 Aug 2019
    9.8
    Critical

    CVE-2019-15149

    Last Modified: 21 Nov 2024

    core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism

    Published: 18 Aug 2019