CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-8932

    Last Modified: 21 Nov 2024

    Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-12914

    Last Modified: 21 Nov 2024

    Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-12911

    Last Modified: 21 Nov 2024

    Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-1010283

    Last Modified: 21 Nov 2024

    Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. The impact is: Loss of Confidentiality. The component is: function data_on_connection() in src/callback.c. The attack vector is: network connectivity. The fixed version is: 12.0.1-4 and later.

    Published: 17 Jul 2019
    5.9
    Medium

    CVE-2019-13636

    Last Modified: 21 Nov 2024

    In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2019-1010287

    Last Modified: 21 Nov 2024

    Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

    Published: 17 Jul 2019
    7.3
    High

    CVE-2019-12876

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-11535

    Last Modified: 21 Nov 2024

    Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended for use beyond the web UI.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13447

    Last Modified: 21 Nov 2024

    An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2019-13448

    Last Modified: 21 Nov 2024

    An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could exploit the vulnerable function in order to prepare an XSS payload to send to the product's clients.

    Published: 17 Jul 2019
    5.4
    Medium

    CVE-2019-13493

    Last Modified: 21 Nov 2024

    In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13577

    Last Modified: 21 Nov 2024

    SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.

    Published: 17 Jul 2019
    5.3
    Medium

    CVE-2019-13584

    Last Modified: 21 Nov 2024

    The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13585

    Last Modified: 21 Nov 2024

    The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13614

    Last Modified: 21 Nov 2024

    CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13613

    Last Modified: 21 Nov 2024

    CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which allows a remote attacker to achieve code execution or denial of service by sending a crafted payload to the listening server.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-12175

    Last Modified: 21 Nov 2024

    In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka KRB) protocol parser leads to DoS because a case-type index is mishandled.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2019-1010091

    Last Modified: 21 Nov 2024

    tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2019-13346

    Last Modified: 21 Nov 2024

    In MyT 1.5.1, the User[username] parameter has XSS.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2019-12475

    Last Modified: 21 Nov 2024

    In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-13403

    Last Modified: 21 Nov 2024

    Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13573

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

    Published: 17 Jul 2019
    6.5
    Medium

    CVE-2019-13453

    Last Modified: 21 Nov 2024

    Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a denial of service. This is related to zipheadio.h:readUint32() and zipfile.cpp:Zipfile::Zipfile().

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-4430

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162887.

    Published: 17 Jul 2019
    5.4
    Medium

    CVE-2019-4211

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159131.

    Published: 17 Jul 2019
    4.3
    Medium

    CVE-2019-4194

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 is missing function level access control that could allow a user to delete authorized resources. IBM X-Force ID: 159033.

    Published: 17 Jul 2019
    3.3
    Low

    CVE-2019-4054

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.

    Published: 17 Jul 2019
    5.3
    Medium

    CVE-2018-2022

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 155346.

    Published: 17 Jul 2019
    6.1
    Medium

    CVE-2018-2021

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155345.

    Published: 17 Jul 2019
    5.4
    Medium

    CVE-2018-1921

    Last Modified: 21 Nov 2024

    IBM Campaign 9.1.0, 9.1.2, 10.1, and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152857.

    Published: 17 Jul 2019
    6.5
    Medium

    CVE-2019-1010084

    Last Modified: 21 Nov 2024

    Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The component is: Incorrect calls to _ensure_auth() wrapper result in authentication-checking not being applied to al routes.

    Published: 17 Jul 2019
    —
    Unknown

    CVE-2019-13446

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Jul 2019
    4.3
    Medium

    CVE-2019-9849

    Last Modified: 21 Nov 2024

    LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-9848

    Last Modified: 21 Nov 2024

    LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

    Published: 17 Jul 2019
    9.1
    Critical

    CVE-2019-13625

    Last Modified: 21 Nov 2024

    NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.

    Published: 17 Jul 2019
    9.8
    Critical

    CVE-2019-13624

    Last Modified: 21 Nov 2024

    In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.

    Published: 17 Jul 2019
    7.8
    High

    CVE-2019-13623

    Last Modified: 21 Nov 2024

    In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.

    Published: 17 Jul 2019
    6.5
    Medium

    CVE-2019-10352

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-13619

    Last Modified: 21 Nov 2024

    In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.

    Published: 17 Jul 2019
    7.5
    High

    CVE-2019-10353

    Last Modified: 21 Nov 2024

    CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.

    Published: 17 Jul 2019
    8.1
    High

    CVE-2019-17543

    Last Modified: 21 Nov 2024

    LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states "only a few specific / uncommon usages of the API are at risk."

    Published: 17 Jul 2019
    4.3
    Medium

    CVE-2019-10354

    Last Modified: 21 Nov 2024

    A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

    Published: 17 Jul 2019
    6.5
    Medium

    CVE-2019-13626

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.

    Published: 17 Jul 2019
    5.3
    Medium

    CVE-2019-3571

    Last Modified: 21 Nov 2024

    An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.

    Published: 16 Jul 2019
    8.8
    High

    CVE-2019-6160

    Last Modified: 21 Nov 2024

    A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.

    Published: 16 Jul 2019
    3.9
    Low

    CVE-2019-9700

    Last Modified: 21 Nov 2024

    Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic.

    Published: 16 Jul 2019
    8.8
    High

    CVE-2018-13442

    Last Modified: 21 Nov 2024

    SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.

    Published: 16 Jul 2019
    7.3
    High

    CVE-2019-12834

    Last Modified: 21 Nov 2024

    In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

    Published: 16 Jul 2019
    9.8
    Critical

    CVE-2019-12985

    Last Modified: 21 Nov 2024

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

    Published: 16 Jul 2019
    7.5
    High

    CVE-2019-10191

    Last Modified: 13 Feb 2025

    A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.

    Published: 16 Jul 2019