CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2019-5407

    Last Modified: 21 Nov 2024

    A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    7.2
    High

    CVE-2019-5406

    Last Modified: 21 Nov 2024

    A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    7.3
    High

    CVE-2019-5405

    Last Modified: 21 Nov 2024

    A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    8.8
    High

    CVE-2019-5404

    Last Modified: 21 Nov 2024

    A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    4.8
    Medium

    CVE-2019-5403

    Last Modified: 21 Nov 2024

    A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    9.4
    Critical

    CVE-2019-5402

    Last Modified: 21 Nov 2024

    A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

    Published: 9 Aug 2019
    6.3
    Medium

    CVE-2019-5400

    Last Modified: 21 Nov 2024

    A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    9.4
    Critical

    CVE-2019-5399

    Last Modified: 21 Nov 2024

    A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-5398

    Last Modified: 21 Nov 2024

    A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    9.4
    Critical

    CVE-2019-5397

    Last Modified: 21 Nov 2024

    A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    9.4
    Critical

    CVE-2019-5396

    Last Modified: 21 Nov 2024

    A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    8.8
    High

    CVE-2019-5395

    Last Modified: 21 Nov 2024

    A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

    Published: 9 Aug 2019
    7.2
    High

    CVE-2017-18486

    Last Modified: 21 Nov 2024

    Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

    Published: 9 Aug 2019
    8.8
    High

    CVE-2019-12805

    Last Modified: 21 Nov 2024

    NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. This can be leveraged for code execution in the context of the current user.

    Published: 9 Aug 2019
    6.1
    Medium

    CVE-2018-20858

    Last Modified: 21 Nov 2024

    Recommender before 2018-07-18 allows XSS.

    Published: 9 Aug 2019
    4.8
    Medium

    CVE-2019-14805

    Last Modified: 21 Nov 2024

    studio/builder_menu.php?page=sets in UNA 10.0.0-RC1 allows XSS via the System Name field under Sets during set editing.

    Published: 9 Aug 2019
    4.8
    Medium

    CVE-2019-14804

    Last Modified: 21 Nov 2024

    studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.

    Published: 9 Aug 2019
    7.5
    High

    CVE-2019-14794

    Last Modified: 21 Nov 2024

    The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.

    Published: 9 Aug 2019
    6.1
    Medium

    CVE-2019-14791

    Last Modified: 21 Nov 2024

    The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-14796

    Last Modified: 21 Nov 2024

    The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_limit parameter.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-14797

    Last Modified: 21 Nov 2024

    The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.

    Published: 9 Aug 2019
    4.9
    Medium

    CVE-2019-14798

    Last Modified: 21 Nov 2024

    The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-14801

    Last Modified: 21 Nov 2024

    The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-14785

    Last Modified: 21 Nov 2024

    The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.

    Published: 9 Aug 2019
    6.1
    Medium

    CVE-2016-10865

    Last Modified: 21 Nov 2024

    The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.

    Published: 9 Aug 2019
    6.5
    Medium

    CVE-2019-14312

    Last Modified: 21 Nov 2024

    Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-14787

    Last Modified: 21 Nov 2024

    The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

    Published: 9 Aug 2019
    6.1
    Medium

    CVE-2019-14799

    Last Modified: 21 Nov 2024

    The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.

    Published: 9 Aug 2019
    6.5
    Medium

    CVE-2019-14793

    Last Modified: 21 Nov 2024

    The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2019-14792

    Last Modified: 21 Nov 2024

    The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.

    Published: 9 Aug 2019
    6.5
    Medium

    CVE-2019-10223

    Last Modified: 21 Nov 2024

    A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.

    Published: 9 Aug 2019
    7.1
    High

    CVE-2019-11042

    Last Modified: 21 Nov 2024

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

    Published: 9 Aug 2019
    7.5
    High

    CVE-2019-14806

    Last Modified: 21 Nov 2024

    Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

    Published: 9 Aug 2019
    2.7
    Low

    CVE-2019-14825

    Last Modified: 21 Nov 2024

    A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

    Published: 9 Aug 2019
    7.1
    High

    CVE-2019-11041

    Last Modified: 21 Nov 2024

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

    Published: 9 Aug 2019
    5.5
    Medium

    CVE-2019-14783

    Last Modified: 21 Nov 2024

    On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764.

    Published: 8 Aug 2019
    8.8
    High

    CVE-2016-10862

    Last Modified: 21 Nov 2024

    Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.

    Published: 8 Aug 2019
    7.5
    High

    CVE-2018-20954

    Last Modified: 21 Nov 2024

    The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys.

    Published: 8 Aug 2019
    9.8
    Critical

    CVE-2018-20955

    Last Modified: 21 Nov 2024

    Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.

    Published: 8 Aug 2019
    5.5
    Medium

    CVE-2018-20956

    Last Modified: 21 Nov 2024

    Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.

    Published: 8 Aug 2019
    8.8
    High

    CVE-2018-20957

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.

    Published: 8 Aug 2019
    8.1
    High

    CVE-2018-20960

    Last Modified: 21 Nov 2024

    Nespresso Prodigio devices lack Bluetooth connection security.

    Published: 8 Aug 2019
    6.1
    Medium

    CVE-2017-18484

    Last Modified: 21 Nov 2024

    Cognitoys Dino devices allow XSS via the SSID.

    Published: 8 Aug 2019
    5.4
    Medium

    CVE-2017-18485

    Last Modified: 21 Nov 2024

    Cognitoys Dino devices allow profiles_add.html CSRF.

    Published: 8 Aug 2019
    8.8
    High

    CVE-2016-10863

    Last Modified: 21 Nov 2024

    Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.

    Published: 8 Aug 2019
    8.8
    High

    CVE-2015-9292

    Last Modified: 21 Nov 2024

    6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).

    Published: 8 Aug 2019
    6.5
    Medium

    CVE-2019-14679

    Last Modified: 21 Nov 2024

    core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.

    Published: 8 Aug 2019
    5.7
    Medium

    CVE-2019-14680

    Last Modified: 21 Nov 2024

    The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.

    Published: 8 Aug 2019
    8.8
    High

    CVE-2019-14681

    Last Modified: 21 Nov 2024

    The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.

    Published: 8 Aug 2019
    4.3
    Medium

    CVE-2019-14682

    Last Modified: 21 Nov 2024

    The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.

    Published: 8 Aug 2019