CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-11200

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insufficient checks on the export parameters to mysqldump, which can lead to execution of arbitrary binaries on the server. (Malicious binaries can be uploaded by abusing other functionalities of the application.)

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2019-11199

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2015-6253

    Last Modified: 21 Nov 2024

    edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2015-6960

    Last Modified: 21 Nov 2024

    edx-platform before 2015-09-17 allows XSS via a team name.

    Published: 29 Jul 2019
    6.5
    Medium

    CVE-2015-9288

    Last Modified: 21 Nov 2024

    The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials

    Published: 29 Jul 2019
    5.3
    Medium

    CVE-2019-12743

    Last Modified: 21 Nov 2024

    HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

    Published: 29 Jul 2019
    6.5
    Medium

    CVE-2019-6726

    Last Modified: 21 Nov 2024

    The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_postratings_clear_fastest_cache and rm_folder_recursively in wpFastestCache.php mishandle ../ in an HTTP Referer header.

    Published: 29 Jul 2019
    8.3
    High

    CVE-2019-12948

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

    Published: 29 Jul 2019
    7.8
    High

    CVE-2019-14267

    Last Modified: 21 Nov 2024

    PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.

    Published: 29 Jul 2019
    7.1
    High

    CVE-2019-13103

    Last Modified: 12 May 2026

    A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data.

    Published: 29 Jul 2019
    —
    Unknown

    CVE-2019-12613

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further investigation showed that it was not a security issue in customer-controlled software. Notes: recovery of a public key is not a security concern as per its public nature

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-1020002

    Last Modified: 21 Nov 2024

    Pterodactyl before 0.7.14 with 2FA allows credential sniffing.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-1020004

    Last Modified: 21 Nov 2024

    Tridactyl before 1.16.0 allows fake key events.

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2019-1020007

    Last Modified: 21 Nov 2024

    Dependency-Track before 3.5.1 allows XSS.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-1020009

    Last Modified: 21 Nov 2024

    Fleet before 2.1.2 allows exposure of SMTP credentials.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2019-1020008

    Last Modified: 21 Nov 2024

    stacktable.js before 1.0.4 allows XSS.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2019-1020006

    Last Modified: 21 Nov 2024

    invenio-app before 1.1.1 allows host header injection.

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2019-1105

    Last Modified: 20 May 2025

    A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user. The security update addresses the vulnerability by correcting how Outlook for Android parses specially crafted email messages.

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2019-1020005

    Last Modified: 21 Nov 2024

    invenio-communities before 1.0.0a20 allows XSS.

    Published: 29 Jul 2019
    5.4
    Medium

    CVE-2019-1020003

    Last Modified: 21 Nov 2024

    invenio-records before 1.2.2 allows XSS.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2019-1020019

    Last Modified: 21 Nov 2024

    invenio-previewer before 1.0.0a12 allows XSS.

    Published: 29 Jul 2019
    7.3
    High

    CVE-2019-1020018

    Last Modified: 21 Nov 2024

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.

    Published: 29 Jul 2019
    5.5
    Medium

    CVE-2019-10207

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.

    Published: 29 Jul 2019
    5.3
    Medium

    CVE-2019-1020017

    Last Modified: 21 Nov 2024

    Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2019-1020016

    Last Modified: 21 Nov 2024

    ASH-AIO before 2.0.0.3 allows an open redirect.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-1020015

    Last Modified: 21 Nov 2024

    graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.

    Published: 29 Jul 2019
    5.5
    Medium

    CVE-2019-1020014

    Last Modified: 21 Nov 2024

    docker-credential-helpers before 0.6.3 has a double free in the List functions.

    Published: 29 Jul 2019
    5.3
    Medium

    CVE-2019-1020013

    Last Modified: 21 Nov 2024

    parse-server before 3.6.0 allows account enumeration.

    Published: 29 Jul 2019
    7.5
    High

    CVE-2019-1020012

    Last Modified: 21 Nov 2024

    parse-server before 3.4.1 allows DoS after any POST to a volatile class.

    Published: 29 Jul 2019
    7.2
    High

    CVE-2019-1020011

    Last Modified: 21 Nov 2024

    SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.

    Published: 29 Jul 2019
    6.1
    Medium

    CVE-2019-1020010

    Last Modified: 21 Nov 2024

    Misskey before 10.102.4 allows hijacking a user's token.

    Published: 29 Jul 2019
    7.8
    High

    CVE-2019-14373

    Last Modified: 21 Nov 2024

    An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer over-read in libpng via a crafted flif file.

    Published: 28 Jul 2019
    6.5
    Medium

    CVE-2019-14372

    Last Modified: 21 Nov 2024

    In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.

    Published: 28 Jul 2019
    6.5
    Medium

    CVE-2019-14371

    Last Modified: 21 Nov 2024

    An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

    Published: 28 Jul 2019
    7.8
    High

    CVE-2019-14368

    Last Modified: 21 Nov 2024

    Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14364

    Last Modified: 21 Nov 2024

    An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter.

    Published: 28 Jul 2019
    9.8
    Critical

    CVE-2019-14363

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP SSDP packet.

    Published: 28 Jul 2019
    5.4
    Medium

    CVE-2019-14362

    Last Modified: 21 Nov 2024

    Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.

    Published: 28 Jul 2019
    7.8
    High

    CVE-2019-14352

    Last Modified: 21 Nov 2024

    In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applications

    Published: 28 Jul 2019
    8.8
    High

    CVE-2019-14351

    Last Modified: 21 Nov 2024

    EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14350

    Last Modified: 21 Nov 2024

    EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can inject JavaScript code in the body parameter during api/v1/KnowledgeBaseArticle knowledge-base record creation.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14349

    Last Modified: 21 Nov 2024

    EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14331

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14330

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14329

    Last Modified: 21 Nov 2024

    An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A malicious attacker can modify the parameter name to contain JavaScript code.

    Published: 28 Jul 2019
    8.8
    High

    CVE-2019-14328

    Last Modified: 21 Nov 2024

    The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

    Published: 28 Jul 2019
    7.5
    High

    CVE-2019-14323

    Last Modified: 21 Nov 2024

    SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte. This results in a crash of the server, but only when strict stack checking is enabled. This is caused by an off-by-one error in ssdp_recv in ssdpd.c.

    Published: 28 Jul 2019
    7.5
    High

    CVE-2019-14322

    Last Modified: 21 Nov 2024

    In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

    Published: 28 Jul 2019
    6.1
    Medium

    CVE-2019-14315

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.

    Published: 28 Jul 2019
    7.5
    High

    CVE-2019-16161

    Last Modified: 21 Nov 2024

    Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.

    Published: 28 Jul 2019