CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2019-14547

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin selects the particular file from the list of all attachments. The attacker could inject the JavaScript inside the filename and send it to users, thus helping him steal victims' cookies (hence compromising their accounts).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2019-14548

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using the Knowledge Base feature in the tab list. The attacker could inject malicious JavaScript inside the body of the article, thus helping him steal victims' cookies (hence compromising their accounts).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2019-14546

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims' cookies (hence compromising their accounts).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2019-14550

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside the add tab list feature, which would fire when a user clicks on the Edit Dashboard button, thus helping him steal victims' cookies (hence compromising their accounts).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2019-14549

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in these values of an entity, thus stealing user cookies when someone visits the publicly accessible link.

    Published: 5 Aug 2019
    9.1
    Critical

    CVE-2019-5502

    Last Modified: 21 Nov 2024

    SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.

    Published: 5 Aug 2019
    3.3
    Low

    CVE-2019-10994

    Last Modified: 21 Nov 2024

    Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow an attacker to obtain sensitive information. The attacker must have local access to the system. A CVSS v3 base score of 2.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

    Published: 5 Aug 2019
    7.8
    High

    CVE-2019-10980

    Last Modified: 21 Nov 2024

    A type confusion vulnerability may be exploited when LAquis SCADA 4.3.1.71 processes a specially crafted project file. This may allow an attacker to execute remote code. The attacker must have local access to the system. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

    Published: 5 Aug 2019
    5.5
    Medium

    CVE-2019-14665

    Last Modified: 21 Nov 2024

    Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.

    Published: 5 Aug 2019
    7.1
    High

    CVE-2019-12264

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

    Published: 5 Aug 2019
    6.1
    Medium

    CVE-2019-11198

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) #300583 - List Manager Dashboard module, (2) #307638 - Campaign Creator module, (3) #316994 - Attributes field, (4) I#316995 - Icon Selection module, (5) #317000 - Latitude field, (6) #317000 - Longitude field, (7) #317017 - UploadPackage2.aspx module, (8) #317072 - Context menu, or (9) I#317073 - Insert from Template dialog.

    Published: 5 Aug 2019
    6.3
    Medium

    CVE-2019-3800

    Last Modified: 21 Nov 2024

    CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

    Published: 5 Aug 2019
    6.8
    Medium

    CVE-2019-3717

    Last Modified: 21 Nov 2024

    Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

    Published: 5 Aug 2019
    7.5
    High

    CVE-2019-11270

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.

    Published: 5 Aug 2019
    9.8
    Critical

    CVE-2019-14348

    Last Modified: 21 Nov 2024

    The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

    Published: 5 Aug 2019
    4.4
    Medium

    CVE-2019-4284

    Last Modified: 21 Nov 2024

    IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token that is printed to log files, which could be used to log in to the system as another user. IBM X-Force ID: 160512.

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2019-4261

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages. IBM X-Force ID: 160013.

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2016-10775

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2016-10774

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows self XSS in the tail_ea4_migration.cgi interface (SEC-172).

    Published: 5 Aug 2019
    8.8
    High

    CVE-2016-10773

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).

    Published: 5 Aug 2019
    3.3
    Low

    CVE-2016-10772

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).

    Published: 5 Aug 2019
    8.1
    High

    CVE-2016-10771

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2016-10770

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).

    Published: 5 Aug 2019
    6.1
    Medium

    CVE-2016-10769

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2016-10768

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2016-10767

    Last Modified: 21 Nov 2024

    cPanel before 60.0.25 allows stored XSS in the WHM Repair Mailbox Permissions interface (SEC-159).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18482

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2017-18481

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18480

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18479

    Last Modified: 21 Nov 2024

    In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18478

    Last Modified: 21 Nov 2024

    In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18477

    Last Modified: 21 Nov 2024

    In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).

    Published: 5 Aug 2019
    7.5
    High

    CVE-2017-18476

    Last Modified: 21 Nov 2024

    Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).

    Published: 5 Aug 2019
    8.8
    High

    CVE-2017-18475

    Last Modified: 21 Nov 2024

    In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).

    Published: 5 Aug 2019
    6.5
    Medium

    CVE-2017-18474

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2017-18473

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).

    Published: 5 Aug 2019
    6.1
    Medium

    CVE-2017-18472

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).

    Published: 5 Aug 2019
    5.4
    Medium

    CVE-2017-18471

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).

    Published: 5 Aug 2019
    8.8
    High

    CVE-2017-18470

    Last Modified: 21 Nov 2024

    cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).

    Published: 5 Aug 2019
    6.3
    Medium

    CVE-2017-18469

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).

    Published: 5 Aug 2019
    6.3
    Medium

    CVE-2017-18468

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).

    Published: 5 Aug 2019
    4.3
    Medium

    CVE-2017-18467

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).

    Published: 5 Aug 2019
    4.4
    Medium

    CVE-2017-18465

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).

    Published: 5 Aug 2019
    2.7
    Low

    CVE-2017-18466

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).

    Published: 5 Aug 2019
    4.9
    Medium

    CVE-2017-18464

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).

    Published: 5 Aug 2019
    7.5
    High

    CVE-2017-18462

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).

    Published: 5 Aug 2019
    7.5
    High

    CVE-2019-14521

    Last Modified: 21 Nov 2024

    The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.

    Published: 5 Aug 2019
    4.9
    Medium

    CVE-2019-14525

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

    Published: 5 Aug 2019
    5.5
    Medium

    CVE-2019-14663

    Last Modified: 21 Nov 2024

    Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.

    Published: 5 Aug 2019
    5.5
    Medium

    CVE-2019-14662

    Last Modified: 21 Nov 2024

    Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.

    Published: 5 Aug 2019