CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-13983

    Last Modified: 21 Nov 2024

    Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13984

    Last Modified: 21 Nov 2024

    Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demonstrated by the EICAR Anti-Virus Test File.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-1010247

    Last Modified: 21 Nov 2024

    ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecting the user to a phishing page or interacting with the application on behalf of the user. The component is: File: src/mod_auth_openidc.c, Line: 3109. The fixed version is: 2.3.10.2.

    Published: 19 Jul 2019
    7.5
    High

    CVE-2019-12946

    Last Modified: 21 Nov 2024

    Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-1010151

    Last Modified: 21 Nov 2024

    zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.

    Published: 19 Jul 2019
    7
    High

    CVE-2019-11552

    Last Modified: 21 Nov 2024

    Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13978

    Last Modified: 21 Nov 2024

    Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.

    Published: 19 Jul 2019
    5.4
    Medium

    CVE-2019-13977

    Last Modified: 21 Nov 2024

    index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13974

    Last Modified: 21 Nov 2024

    LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.

    Published: 19 Jul 2019
    9.8
    Critical

    CVE-2019-13973

    Last Modified: 21 Nov 2024

    LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-13972

    Last Modified: 21 Nov 2024

    LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-13971

    Last Modified: 21 Nov 2024

    OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.

    Published: 19 Jul 2019
    6.1
    Medium

    CVE-2019-13970

    Last Modified: 21 Nov 2024

    In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.

    Published: 19 Jul 2019
    8.8
    High

    CVE-2019-13969

    Last Modified: 21 Nov 2024

    Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.

    Published: 19 Jul 2019
    5.5
    Medium

    CVE-2019-13648

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user can cause a denial of service (TM Bad Thing exception and system crash) via a sigreturn() system call that sends a crafted signal frame. This affects arch/powerpc/kernel/signal_32.c and arch/powerpc/kernel/signal_64.c.

    Published: 19 Jul 2019
    6.5
    Medium

    CVE-2019-7963

    Last Modified: 21 Nov 2024

    Adobe Bridge CC version 9.0.2 and earlier versions have an out of bound read vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 18 Jul 2019
    6.5
    Medium

    CVE-2019-7953

    Last Modified: 21 Nov 2024

    Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.

    Published: 18 Jul 2019
    6.1
    Medium

    CVE-2019-7954

    Last Modified: 21 Nov 2024

    Adobe Experience Manager version 6.4 and ealier have a Stored Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.

    Published: 18 Jul 2019
    6.1
    Medium

    CVE-2019-7955

    Last Modified: 21 Nov 2024

    Adobe Experience Manager version 6.4 and ealier have a Reflected Cross-site Scripting vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.

    Published: 18 Jul 2019
    7.8
    High

    CVE-2019-7956

    Last Modified: 21 Nov 2024

    Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-7843

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Insufficient input validation vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-7941

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Information Exposure Through an Error Message vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-7846

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-7847

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-7848

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Inadequate access control vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-7850

    Last Modified: 21 Nov 2024

    Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-13962

    Last Modified: 21 Nov 2024

    lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

    Published: 18 Jul 2019
    8.8
    High

    CVE-2019-13961

    Last Modified: 21 Nov 2024

    A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.

    Published: 18 Jul 2019
    6.5
    Medium

    CVE-2019-13959

    Last Modified: 21 Nov 2024

    In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.

    Published: 18 Jul 2019
    4.3
    Medium

    CVE-2019-8286

    Last Modified: 21 Nov 2024

    Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6

    Published: 18 Jul 2019
    8.8
    High

    CVE-2019-1010112

    Last Modified: 21 Nov 2024

    OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-1010279

    Last Modified: 21 Nov 2024

    Open Information Security Foundation Suricata prior to version 4.1.3 is affected by: Denial of Service - TCP/HTTP detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed sequence of network packets. The component is: detect.c (https://github.com/OISF/suricata/pull/3625/commits/d8634daf74c882356659addb65fb142b738a186b). The attack vector is: An attacker can trigger the vulnerability by a specifically crafted network TCP session. The fixed version is: 4.1.3.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-1010246

    Last Modified: 21 Nov 2024

    MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content disclosure (e.g. username, password). The component is: The API call in the function allowAction() in NewslettersController.php. The attack vector is: HTTP Get request. The fixed version is: c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9.

    Published: 18 Jul 2019
    7.2
    High

    CVE-2019-3592

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-1010248

    Last Modified: 21 Nov 2024

    Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed version is: 1.12.1.

    Published: 18 Jul 2019
    4.9
    Medium

    CVE-2019-1010249

    Last Modified: 21 Nov 2024

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is: network management and connectivity.

    Published: 18 Jul 2019
    4.9
    Medium

    CVE-2019-1010250

    Last Modified: 21 Nov 2024

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is: network management and connectivity.

    Published: 18 Jul 2019
    7.5
    High

    CVE-2019-1010251

    Last Modified: 21 Nov 2024

    Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

    Published: 18 Jul 2019
    4.9
    Medium

    CVE-2019-1010252

    Last Modified: 21 Nov 2024

    The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management and connectivity.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-13956

    Last Modified: 21 Nov 2024

    Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).

    Published: 18 Jul 2019
    4.4
    Medium

    CVE-2019-11230

    Last Modified: 21 Nov 2024

    In Avast Antivirus before 19.4, a local administrator can trick the product into renaming arbitrary files by replacing the Logs\Update.log file with a symlink. The next time the product attempts to write to the log file, the target of the symlink is renamed. This defect can be exploited to rename a critical product file (e.g., AvastSvc.exe), causing the product to fail to start on the next system restart.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-1010259

    Last Modified: 21 Nov 2024

    SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is: specially crafted password string. The fixed version is: 2018.3.4.

    Published: 18 Jul 2019
    6.1
    Medium

    CVE-2019-1010261

    Last Modified: 21 Nov 2024

    Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in browser. The component is: go-get URL generation - PR to fix: https://github.com/go-gitea/gitea/pull/5905. The attack vector is: victim must open a specifically crafted URL. The fixed version is: 1.7.1 and later.

    Published: 18 Jul 2019
    —
    Unknown

    CVE-2019-1010262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-1010142. Reason: This candidate is a reservation duplicate of CVE-2019-1010142. Notes: All CVE users should reference CVE-2019-1010142 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-13952

    Last Modified: 21 Nov 2024

    The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv6 address in zone data.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-13951

    Last Modified: 21 Nov 2024

    The set_ipv4() function in zscan_rfc1035.rl in gdnsd 3.x before 3.2.1 has a stack-based buffer overflow via a long and malformed IPv4 address in zone data.

    Published: 18 Jul 2019
    6.5
    Medium

    CVE-2019-1010065

    Last Modified: 21 Nov 2024

    The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image.

    Published: 18 Jul 2019
    9.8
    Critical

    CVE-2019-1010268

    Last Modified: 21 Nov 2024

    Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance: https://bitbucket.org/jakobsg/ladon/src/42944fc012a3a48214791c120ee5619434505067/src/ladon/interfaces/soap.py#lines-688. The attack vector is: Send a specially crafted SOAP call.

    Published: 18 Jul 2019
    5.4
    Medium

    CVE-2019-13950

    Last Modified: 21 Nov 2024

    index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.

    Published: 18 Jul 2019
    8.8
    High

    CVE-2019-13949

    Last Modified: 21 Nov 2024

    SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.

    Published: 18 Jul 2019