CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-7964

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5, and 6.4 have an authentication bypass vulnerability. Successful exploitation could lead to remote code execution.

    Published: 16 Aug 2019
    5.4
    Medium

    CVE-2019-15120

    Last Modified: 21 Nov 2024

    The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

    Published: 16 Aug 2019
    5.5
    Medium

    CVE-2019-15119

    Last Modified: 17 Apr 2025

    lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.

    Published: 16 Aug 2019
    5.5
    Medium

    CVE-2019-15118

    Last Modified: 21 Nov 2024

    check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2017-18548

    Last Modified: 21 Nov 2024

    The note-press plugin before 0.1.2 for WordPress has SQL injection.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2016-10904

    Last Modified: 21 Nov 2024

    The olimometer plugin before 2.57 for WordPress has SQL injection.

    Published: 16 Aug 2019
    —
    Unknown

    CVE-2018-13884

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2015-9325

    Last Modified: 21 Nov 2024

    The visitors-online plugin before 0.4 for WordPress has SQL injection.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2015-9326

    Last Modified: 21 Nov 2024

    The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.

    Published: 16 Aug 2019
    8.8
    High

    CVE-2019-14923

    Last Modified: 21 Nov 2024

    EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2019-15091

    Last Modified: 21 Nov 2024

    filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

    Published: 16 Aug 2019
    4.8
    Medium

    CVE-2019-15108

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.

    Published: 16 Aug 2019
    4.6
    Medium

    CVE-2016-10894

    Last Modified: 21 Nov 2024

    xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).

    Published: 16 Aug 2019
    8.8
    High

    CVE-2019-15104

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

    Published: 16 Aug 2019
    8.8
    High

    CVE-2019-15105

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2019-15106

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2019-15107

    Last Modified: 6 Nov 2025

    An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

    Published: 16 Aug 2019
    4.6
    Medium

    CVE-2019-15098

    Last Modified: 21 Nov 2024

    drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

    Published: 16 Aug 2019
    7.5
    High

    CVE-2019-15099

    Last Modified: 21 Nov 2024

    drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

    Published: 16 Aug 2019
    6.1
    Medium

    CVE-2019-15095

    Last Modified: 21 Nov 2024

    DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.

    Published: 16 Aug 2019
    9.8
    Critical

    CVE-2019-5477

    Last Modified: 21 Nov 2024

    A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. The underlying vulnerability was addressed in Rexical v1.0.7 and Nokogiri upgraded to this version of Rexical in Nokogiri v1.10.4.

    Published: 16 Aug 2019
    7.8
    High

    CVE-2019-15117

    Last Modified: 21 Nov 2024

    parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.

    Published: 16 Aug 2019
    7.8
    High

    CVE-2018-20969

    Last Modified: 21 Nov 2024

    do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

    Published: 16 Aug 2019
    6.7
    Medium

    CVE-2019-15090

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.

    Published: 15 Aug 2019
    7.8
    High

    CVE-2019-15084

    Last Modified: 21 Nov 2024

    Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.

    Published: 15 Aug 2019
    9.1
    Critical

    CVE-2018-14062

    Last Modified: 21 Nov 2024

    The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.

    Published: 15 Aug 2019
    8.8
    High

    CVE-2019-12792

    Last Modified: 21 Nov 2024

    A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.

    Published: 15 Aug 2019
    8.8
    High

    CVE-2019-12791

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.

    Published: 15 Aug 2019
    8.1
    High

    CVE-2019-3974

    Last Modified: 21 Nov 2024

    Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition.

    Published: 15 Aug 2019
    8.8
    High

    CVE-2019-12809

    Last Modified: 21 Nov 2024

    Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for code execution.

    Published: 15 Aug 2019
    8.8
    High

    CVE-2019-13516

    Last Modified: 21 Nov 2024

    In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.

    Published: 15 Aug 2019
    7.8
    High

    CVE-2019-13514

    Last Modified: 21 Nov 2024

    In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger a use-after-free vulnerability, which may allow information disclosure, remote code execution, or crash of the application.

    Published: 15 Aug 2019
    6.5
    Medium

    CVE-2019-13515

    Last Modified: 21 Nov 2024

    OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

    Published: 15 Aug 2019
    7.8
    High

    CVE-2019-13513

    Last Modified: 21 Nov 2024

    In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger multiple out-of-bounds read vulnerabilities, which may allow information disclosure, remote code execution, or crash of the application.

    Published: 15 Aug 2019
    7.8
    High

    CVE-2019-13510

    Last Modified: 17 Dec 2024

    Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

    Published: 15 Aug 2019
    3.3
    Low

    CVE-2019-13511

    Last Modified: 17 Dec 2024

    Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.

    Published: 15 Aug 2019
    3.3
    Low

    CVE-2019-13512

    Last Modified: 21 Nov 2024

    Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an attacker to read limited information from the device.

    Published: 15 Aug 2019
    5.3
    Medium

    CVE-2018-14672

    Last Modified: 25 Jun 2025

    In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.

    Published: 15 Aug 2019
    7.5
    High

    CVE-2019-9012

    Last Modified: 21 Nov 2024

    An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.

    Published: 15 Aug 2019
    9.8
    Critical

    CVE-2018-14671

    Last Modified: 25 Jun 2025

    In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.

    Published: 15 Aug 2019
    9.8
    Critical

    CVE-2019-9010

    Last Modified: 21 Nov 2024

    An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.

    Published: 15 Aug 2019
    7.5
    High

    CVE-2018-14669

    Last Modified: 25 Jun 2025

    ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.

    Published: 15 Aug 2019
    8.8
    High

    CVE-2018-14668

    Last Modified: 25 Jun 2025

    In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.

    Published: 15 Aug 2019
    9.8
    Critical

    CVE-2018-14670

    Last Modified: 25 Jun 2025

    Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.

    Published: 15 Aug 2019
    5.4
    Medium

    CVE-2018-12101

    Last Modified: 21 Nov 2024

    CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.

    Published: 15 Aug 2019
    6.5
    Medium

    CVE-2018-12357

    Last Modified: 21 Nov 2024

    Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

    Published: 15 Aug 2019
    6.5
    Medium

    CVE-2018-14008

    Last Modified: 21 Nov 2024

    Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

    Published: 15 Aug 2019
    5.4
    Medium

    CVE-2018-17790

    Last Modified: 21 Nov 2024

    Prospecta Master Data Online (MDO) 2.0 has Stored XSS.

    Published: 15 Aug 2019
    5.5
    Medium

    CVE-2017-14232

    Last Modified: 21 Nov 2024

    The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif file.

    Published: 15 Aug 2019
    9.8
    Critical

    CVE-2019-11187

    Last Modified: 21 Nov 2024

    Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

    Published: 15 Aug 2019