CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-17351

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef36ab967c7.

    Published: 22 Jul 2019
    9.8
    Critical

    CVE-2019-14231

    Last Modified: 21 Nov 2024

    An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.

    Published: 21 Jul 2019
    9.8
    Critical

    CVE-2019-14230

    Last Modified: 21 Nov 2024

    An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14215

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14214

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling a "t.hidden = true" function.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14213

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of the signature dictionary during CSG_SignatureF and CPDF_Document destruction.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14212

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling certain XFA JavaScript due to the use of, or access to, a NULL pointer without proper validation on the object.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14211

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validation of the existence of an object prior to performing operations on that object when executing JavaScript.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14210

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object.

    Published: 21 Jul 2019
    9.8
    Critical

    CVE-2019-14209

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to data desynchrony when adding AcroForm.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14208

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereference and crash when getting a PDF object from a document, or parsing a certain portfolio that contains a null dictionary.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14207

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child and parent object (caused by an append error).

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14206

    Last Modified: 21 Nov 2024

    An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.

    Published: 21 Jul 2019
    7.5
    High

    CVE-2019-14205

    Last Modified: 21 Nov 2024

    A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] parameter in adaptive-images-script.php.

    Published: 21 Jul 2019
    —
    Unknown

    CVE-2002-0390

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0639. Reason: This candidate is a reservation duplicate of CVE-2002-0639. Notes: All CVE users should reference CVE-2002-0639 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2019
    8.8
    High

    CVE-2019-12934

    Last Modified: 21 Nov 2024

    An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2018-17210

    Last Modified: 21 Nov 2024

    An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-9229

    Last Modified: 21 Nov 2024

    An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-12815

    Last Modified: 4 Nov 2025

    An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

    Published: 19 Jul 2019
    7.5
    High

    CVE-2019-9228

    Last Modified: 21 Nov 2024

    An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-13569

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-12725

    Last Modified: 21 Nov 2024

    Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-11990

    Last Modified: 21 Nov 2024

    Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603 * For customers with release UIoT 1.5, fixes are made available with 1.5 RP503 HF3 * For customers with release older than 1.5, such as 1.4.0, 1.4.1, 1.4.2 and 1.2.4.2, the resolution will be to upgrade to 1.5 RP503 HF3 or 1.6 RP603 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.

    Published: 19 Jul 2019
    5.9
    Medium

    CVE-2019-11989

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.

    Published: 19 Jul 2019
    8.1
    High

    CVE-2019-1579

    Last Modified: 4 Nov 2025

    Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.

    Published: 19 Jul 2019
    6.7
    Medium

    CVE-2019-7590

    Last Modified: 21 Nov 2024

    ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on the system. This issue affects: Exacq Technologies, Inc. exacqVision Server 9.6; 9.8. This issue does not affect: Exacq Technologies, Inc. exacqVision Server version 9.4 and prior versions; 19.03. It is not known whether this issue affects: Exacq Technologies, Inc. exacqVision Server versions prior to 8.4.

    Published: 19 Jul 2019
    6.5
    Medium

    CVE-2019-13991

    Last Modified: 21 Nov 2024

    Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.

    Published: 19 Jul 2019
    6.7
    Medium

    CVE-2019-5680

    Last Modified: 21 Nov 2024

    In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.

    Published: 19 Jul 2019
    7.8
    High

    CVE-2019-13989

    Last Modified: 21 Nov 2024

    dpic 2019.06.20 has a Stack-based Buffer Overflow in the wfloat() function in main.c.

    Published: 19 Jul 2019
    4.8
    Medium

    CVE-2019-12821

    Last Modified: 21 Nov 2024

    A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the account using a QR-code. The QR-code follows an easily predictable pattern that depends only on the specific device ID of the robot vacuum cleaner. By generating a QR-code containing information about the device ID, it is possible to connect an arbitrary device and gain full access to it. The device ID has an initial "JSW" substring followed by a six digit number that depends on the specific device.

    Published: 19 Jul 2019
    5.6
    Medium

    CVE-2019-12820

    Last Modified: 21 Nov 2024

    A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, and personal information it communicates with the server, use unencrypted HTTP. As an example, while logging in through the app to a Jisiwei account, the login request is being sent in cleartext. The vulnerability exists in both the Android and iOS version of the app. An attacker could exploit this by using an MiTM attack on the local network to obtain someone's login credentials, which gives them full access to the robot vacuum cleaner.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-12453

    Last Modified: 21 Nov 2024

    In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2018-17792

    Last Modified: 21 Nov 2024

    MDaemon Webmail (formerly WorldClient) has CSRF.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-11553

    Last Modified: 21 Nov 2024

    In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate a user with web restore permission. When requesting the token to do a web restore, an administrator with permission to manage a user could request the token of that user. If the administrator was not authorized to perform web restores but the user was authorized to perform web restores, this would allow the administrator to impersonate the user with greater permissions. In order to exploit this vulnerability, the user would have to be an administrator with access to manage an organization with a user with greater permissions than themselves.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-1010238

    Last Modified: 21 Nov 2024

    Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.

    Published: 19 Jul 2019
    7.5
    High

    CVE-2019-1010239

    Last Modified: 22 Jul 2025

    DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.

    Published: 19 Jul 2019
    —
    Unknown

    CVE-2019-12945

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Jul 2019
    6.5
    Medium

    CVE-2019-1010241

    Last Modified: 21 Nov 2024

    Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-12193

    Last Modified: 21 Nov 2024

    H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.

    Published: 19 Jul 2019
    7.5
    High

    CVE-2019-1010142

    Last Modified: 21 Nov 2024

    scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap. both work.

    Published: 19 Jul 2019
    7.5
    High

    CVE-2019-1010136

    Last Modified: 21 Nov 2024

    ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-1010101

    Last Modified: 21 Nov 2024

    Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377, CWE-379.

    Published: 19 Jul 2019
    7.8
    High

    CVE-2019-1010100

    Last Modified: 21 Nov 2024

    Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is: CAPEC-471, CWE-426, CWE-427.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-1010113

    Last Modified: 21 Nov 2024

    Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might be able to inject arbitrary html and script code into the web site. The component is: jQuery plug-in. The attack vector is: the victim must open a crafted href attribute of a link (A) element.

    Published: 19 Jul 2019
    4.1
    Medium

    CVE-2019-1167

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-1010245

    Last Modified: 21 Nov 2024

    The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is: network connectivity. The fixed version is: 1.15.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13979

    Last Modified: 21 Nov 2024

    In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13980

    Last Modified: 21 Nov 2024

    In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.

    Published: 19 Jul 2019
    5.3
    Medium

    CVE-2019-13981

    Last Modified: 21 Nov 2024

    In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer.

    Published: 19 Jul 2019
    5.3
    Medium

    CVE-2019-13982

    Last Modified: 21 Nov 2024

    interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.

    Published: 19 Jul 2019