CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-7899

    Last Modified: 21 Nov 2024

    Names of disabled downloadable products could be disclosed due to inadequate validation of user input in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2019-7898

    Last Modified: 21 Nov 2024

    Samples of disabled downloadable products are accessible in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to inadequate validation of user input.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7897

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to customer configurations to inject malicious javascript.

    Published: 2 Aug 2019
    7.2
    High

    CVE-2019-7896

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to layouts can execute arbitrary code through a combination of product import, crafted csv file and XML layout update.

    Published: 2 Aug 2019
    7.2
    High

    CVE-2019-7895

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with admin privileges to layouts can execute arbitrary code through a crafted XML layout update.

    Published: 2 Aug 2019
    7.2
    High

    CVE-2019-7892

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to access shipment settings can execute arbitrary code via server-side request forgery.

    Published: 2 Aug 2019
    7.3
    High

    CVE-2019-7890

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-7889

    Last Modified: 21 Nov 2024

    An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with marketing manipulation privileges can invoke methods that alter data of the underlying model followed by corresponding database modifications.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-7888

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to create email templates could leak sensitive data via a malicious email template.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7887

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 when the feature that adds a secret key to the Admin URL is disabled.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7886

    Last Modified: 21 Nov 2024

    A cryptograhic flaw exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. A weak cryptograhic mechanism is used to generate the intialization vector in multiple security relevant contexts.

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-7885

    Last Modified: 21 Nov 2024

    Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2019-7882

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the editor can inject malicious SWF files.

    Published: 2 Aug 2019
    5.4
    Medium

    CVE-2019-7881

    Last Modified: 21 Nov 2024

    A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7880

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to marketing email templates to inject malicious javascript.

    Published: 2 Aug 2019
    6.1
    Medium

    CVE-2019-7877

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manage orders can inject malicious javascript.

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-7876

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to manipulate layouts can insert a malicious payload into the layout.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7875

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to newsletter templates.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-7874

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.

    Published: 2 Aug 2019
    4.3
    Medium

    CVE-2019-7873

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of the store design schedule.

    Published: 2 Aug 2019
    9.8
    Critical

    CVE-2019-14544

    Last Modified: 21 Nov 2024

    routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-7872

    Last Modified: 21 Nov 2024

    An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 due to insufficient authorizations checks. This can be abused by a user with admin privileges to add users to company accounts or modify existing user details.

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-7871

    Last Modified: 21 Nov 2024

    A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code. An authenticated user can bypass security protections that prevent arbitrary PHP script upload via form data injection.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7869

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with permissions to manage customer groups.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7868

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with permissions to manage tax rules.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7867

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to manage orders and order status.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7866

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to edit Product information via the TinyMCE editor.

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-7865

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2019-7864

    Last Modified: 21 Nov 2024

    An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can lead to unauthorized access to order details.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7863

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to products and categories.

    Published: 2 Aug 2019
    4.8
    Medium

    CVE-2019-7862

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7861

    Last Modified: 21 Nov 2024

    Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7860

    Last Modified: 21 Nov 2024

    A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7859

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could result in unauthorized access to uploaded images due to insufficient access control.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7858

    Last Modified: 21 Nov 2024

    A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted in storage of sensitive information with an algorithm that is insufficiently resistant to brute force attacks.

    Published: 2 Aug 2019
    4.3
    Medium

    CVE-2019-7857

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2019-7855

    Last Modified: 21 Nov 2024

    A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abused by an unauthenticated user to discover an invariant used in gift card generation.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7854

    Last Modified: 21 Nov 2024

    An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unauthorized disclosure of company credit history details.

    Published: 2 Aug 2019
    5.3
    Medium

    CVE-2019-7852

    Last Modified: 21 Nov 2024

    A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. Requests for a specific file path could result in a redirect to the URL of the Magento admin panel, disclosing its location to potentially unauthorized parties.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-7851

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-7849

    Last Modified: 21 Nov 2024

    A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.

    Published: 2 Aug 2019
    9.8
    Critical

    CVE-2019-7163

    Last Modified: 21 Nov 2024

    The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.

    Published: 2 Aug 2019
    7.5
    High

    CVE-2019-6969

    Last Modified: 21 Nov 2024

    The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sensitive information such as the Wi-Fi password and the phone number (if VoIP is in use).

    Published: 2 Aug 2019
    6.1
    Medium

    CVE-2019-6968

    Last Modified: 21 Nov 2024

    The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflected.

    Published: 2 Aug 2019
    7.8
    High

    CVE-2019-14541

    Last Modified: 21 Nov 2024

    GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code.

    Published: 2 Aug 2019
    8.8
    High

    CVE-2019-10088

    Last Modified: 21 Nov 2024

    A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Users should upgrade to 1.22 or later.

    Published: 2 Aug 2019
    7.8
    High

    CVE-2019-10094

    Last Modified: 21 Nov 2024

    A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a StackOverflowError in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. Apache Tika users should upgrade to 1.22 or later.

    Published: 2 Aug 2019
    6.5
    Medium

    CVE-2019-10093

    Last Modified: 21 Nov 2024

    In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the pool and lead to very long hangs. Apache Tika users should upgrade to 1.22 or later.

    Published: 2 Aug 2019
    7.8
    High

    CVE-2017-18463

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).

    Published: 2 Aug 2019
    4.3
    Medium

    CVE-2017-18461

    Last Modified: 21 Nov 2024

    cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).

    Published: 2 Aug 2019