CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-14387

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).

    Published: 30 Jul 2019
    7.5
    High

    CVE-2019-14381

    Last Modified: 21 Nov 2024

    libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.

    Published: 30 Jul 2019
    5.4
    Medium

    CVE-2019-14386

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).

    Published: 30 Jul 2019
    7.5
    High

    CVE-2017-18380

    Last Modified: 21 Nov 2024

    edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14327

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.

    Published: 30 Jul 2019
    9.1
    Critical

    CVE-2019-13635

    Last Modified: 21 Nov 2024

    The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14443

    Last Modified: 21 Nov 2024

    An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14442

    Last Modified: 21 Nov 2024

    In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14441

    Last Modified: 21 Nov 2024

    An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-1552

    Last Modified: 21 Nov 2024

    OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --openssldir configuration options. For OpenSSL versions 1.1.0 and 1.1.1, the mingw configuration targets assume that resulting programs and libraries are installed in a Unix-like environment and the default prefix for program installation as well as for OPENSSLDIR should be '/usr/local'. However, mingw programs are Windows programs, and as such, find themselves looking at sub-directories of 'C:/usr/local', which may be world writable, which enables untrusted users to modify OpenSSL's default configuration, insert CA certificates, modify (or even replace) existing engine modules, etc. For OpenSSL 1.0.2, '/usr/local/ssl' is used as default for OPENSSLDIR on all Unix and Windows targets, including Visual C builds. However, some build instructions for the diverse Windows targets on 1.0.2 encourage you to specify your own --prefix. OpenSSL versions 1.1.1, 1.1.0 and 1.0.2 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c). Fixed in OpenSSL 1.1.0l (Affected 1.1.0-1.1.0k). Fixed in OpenSSL 1.0.2t (Affected 1.0.2-1.0.2s).

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5857

    Last Modified: 21 Nov 2024

    Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5865

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 30 Jul 2019
    7.5
    High

    CVE-2019-14439

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

    Published: 30 Jul 2019
    9.6
    Critical

    CVE-2019-5850

    Last Modified: 21 Nov 2024

    Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5856

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5863

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-5864

    Last Modified: 21 Nov 2024

    Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5851

    Last Modified: 21 Nov 2024

    Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5852

    Last Modified: 21 Nov 2024

    Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5853

    Last Modified: 21 Nov 2024

    Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5854

    Last Modified: 21 Nov 2024

    Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5855

    Last Modified: 21 Nov 2024

    Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5858

    Last Modified: 21 Nov 2024

    Incorrect security UI in MacOS services integration in Google Chrome on OS X prior to 76.0.3809.87 allowed a local attacker to execute arbitrary code via a crafted HTML page.

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-5859

    Last Modified: 21 Nov 2024

    Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2019-5860

    Last Modified: 21 Nov 2024

    Use after free in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-5861

    Last Modified: 21 Nov 2024

    Insufficient data validation in Blink in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to bypass anti-clickjacking policy via a crafted HTML page.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-5862

    Last Modified: 21 Nov 2024

    Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2015-9290

    Last Modified: 21 Nov 2024

    In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-18570

    Last Modified: 21 Nov 2024

    Planon before Live Build 41 has XSS.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-3948

    Last Modified: 21 Nov 2024

    The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX V2.623.0000000.7.R, Dahua DH-SD5XXXXX V2.623.0000000.1.R, Dahua DH-SD6XXXXX V2.640.0000000.2.R and V2.623.0000000.1.R, Dahua NVR5XX-4KS2 V3.216.0000006.0.R, Dahua NVR4XXX-4KS2 V3.216.0000006.0.R, and NVR2XXX-4KS2 do not require authentication to access the HTTP endpoint /videotalk. An unauthenticated, remote person can connect to this endpoint and potentionally listen to the audio of the capturing device.

    Published: 29 Jul 2019
    9.8
    Critical

    CVE-2019-14431

    Last Modified: 21 Nov 2024

    In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value provided in the DTLS message.

    Published: 29 Jul 2019
    8.8
    High

    CVE-2019-14418

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.

    Published: 29 Jul 2019
    7.2
    High

    CVE-2019-14417

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to DNS functionality.

    Published: 29 Jul 2019
    7.2
    High

    CVE-2019-14416

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.

    Published: 29 Jul 2019
    4.8
    Medium

    CVE-2019-14415

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.

    Published: 29 Jul 2019
    6.5
    Medium

    CVE-2019-13655

    Last Modified: 21 Nov 2024

    Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.

    Published: 29 Jul 2019
    7.2
    High

    CVE-2018-11772

    Last Modified: 21 Nov 2024

    Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

    Published: 29 Jul 2019
    7.2
    High

    CVE-2018-11774

    Last Modified: 21 Nov 2024

    Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

    Published: 29 Jul 2019
    9.8
    Critical

    CVE-2018-11773

    Last Modified: 21 Nov 2024

    Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered appeared to be resistant to a malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

    Published: 29 Jul 2019
    8.8
    High

    CVE-2018-17213

    Last Modified: 21 Nov 2024

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.

    Published: 29 Jul 2019
    5.3
    Medium

    CVE-2018-17211

    Last Modified: 21 Nov 2024

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.

    Published: 29 Jul 2019
    9.8
    Critical

    CVE-2019-13571

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

    Published: 29 Jul 2019
    9.8
    Critical

    CVE-2019-14271

    Last Modified: 21 Nov 2024

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

    Published: 29 Jul 2019
    7.8
    High

    CVE-2019-11868

    Last Modified: 21 Nov 2024

    See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address to which arbitrary bytes are written to.

    Published: 29 Jul 2019
    8.8
    High

    CVE-2016-10766

    Last Modified: 21 Nov 2024

    edx-platform before 2016-06-06 allows CSRF.

    Published: 29 Jul 2019
    5.3
    Medium

    CVE-2016-10765

    Last Modified: 21 Nov 2024

    edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-13126

    Last Modified: 30 Mar 2026

    An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.

    Published: 29 Jul 2019
    7.4
    High

    CVE-2019-13498

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

    Published: 29 Jul 2019
    8.8
    High

    CVE-2015-5601

    Last Modified: 21 Nov 2024

    edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

    Published: 29 Jul 2019
    8
    High

    CVE-2019-11201

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

    Published: 29 Jul 2019