CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-12539

    Last Modified: 21 Nov 2024

    An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-12540

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-12595

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-12596

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-12597

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-13506

    Last Modified: 21 Nov 2024

    @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.

    Published: 11 Jul 2019
    9.8
    Critical

    CVE-2019-12838

    Last Modified: 21 Nov 2024

    SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-1010003

    Last Modified: 21 Nov 2024

    Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

    Published: 11 Jul 2019
    6.1
    Medium

    CVE-2019-13505

    Last Modified: 21 Nov 2024

    The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.

    Published: 11 Jul 2019
    7.5
    High

    CVE-2019-13503

    Last Modified: 21 Nov 2024

    mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

    Published: 11 Jul 2019
    7.2
    High

    CVE-2019-10135

    Last Modified: 21 Nov 2024

    A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.

    Published: 11 Jul 2019
    6.8
    Medium

    CVE-2019-13631

    Last Modified: 21 Nov 2024

    In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages.

    Published: 11 Jul 2019
    7.5
    High

    CVE-2019-14494

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

    Published: 11 Jul 2019
    6.5
    Medium

    CVE-2019-17371

    Last Modified: 21 Nov 2024

    gif2png 2.5.13 has a memory leak in the writefile function.

    Published: 11 Jul 2019
    8.8
    High

    CVE-2018-17196

    Last Modified: 21 Nov 2024

    In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.

    Published: 11 Jul 2019
    5.9
    Medium

    CVE-2019-12529

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decoding the string. There are no checks to ensure that the length it calculates isn't greater than the input buffer. This leads to adjacent memory being decoded as well. An attacker would not be able to retrieve the decoded data unless the Squid maintainer had configured the display of usernames on error pages.

    Published: 11 Jul 2019
    9.8
    Critical

    CVE-2019-13489

    Last Modified: 21 Nov 2024

    Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-13488

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter to the /register URI, because the jQuery prepend() method is used.

    Published: 10 Jul 2019
    —
    Unknown

    CVE-2019-13381

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-13482

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-13481

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.

    Published: 10 Jul 2019
    7.2
    High

    CVE-2019-5446

    Last Modified: 21 Nov 2024

    Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.

    Published: 10 Jul 2019
    4.9
    Medium

    CVE-2019-5445

    Last Modified: 21 Nov 2024

    DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-5444

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.

    Published: 10 Jul 2019
    5.5
    Medium

    CVE-2019-12804

    Last Modified: 21 Nov 2024

    In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-12803

    Last Modified: 21 Nov 2024

    In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command.

    Published: 10 Jul 2019
    9.1
    Critical

    CVE-2019-0330

    Last Modified: 21 Nov 2024

    The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-0329

    Last Modified: 21 Nov 2024

    SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2019
    7.2
    High

    CVE-2019-0328

    Last Modified: 21 Nov 2024

    ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS commands with privileged rights. An attacker could thereby impact the integrity and availability of the system.

    Published: 10 Jul 2019
    7.2
    High

    CVE-2019-0327

    Last Modified: 21 Nov 2024

    SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-0326

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2019
    4.2
    Medium

    CVE-2019-0325

    Last Modified: 21 Nov 2024

    SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll data of employees in a certain area. Due to this under certain conditions, the user that once had authorization to payroll data of an employee, which was later revoked, may retain access to the same data.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-0322

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-0321

    Last Modified: 21 Nov 2024

    ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-0319

    Last Modified: 21 Nov 2024

    The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attacker could thus mislead a user to believe this information is from the legitimate service when it's not.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-0318

    Last Modified: 21 Nov 2024

    Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-0281

    Last Modified: 21 Nov 2024

    SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2019
    5.9
    Medium

    CVE-2019-11650

    Last Modified: 21 Nov 2024

    A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-10966

    Last Modified: 21 Nov 2024

    In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2019-5221

    Last Modified: 21 Nov 2024

    There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the phone. Affected products: Mate 20 X versions earlier than Ever-L29B 9.1.0.300(C432E3R1P12), versions earlier than Ever-L29B 9.1.0.300(C636E3R2P1), and versions earlier than Ever-L29B 9.1.0.300(C185E3R3P1).

    Published: 10 Jul 2019
    4.6
    Medium

    CVE-2019-5220

    Last Modified: 21 Nov 2024

    There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2).

    Published: 10 Jul 2019
    8.6
    High

    CVE-2019-1873

    Last Modified: 21 Nov 2024

    A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to incomplete input validation of a Secure Sockets Layer (SSL) or Transport Layer Security (TLS) ingress packet header. An attacker could exploit this vulnerability by sending a crafted TLS/SSL packet to an interface on the targeted device. An exploit could allow the attacker to cause the device to reload, which will result in a denial of service (DoS) condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed and transparent firewall mode and in single or multiple context mode. This vulnerability can be triggered by IPv4 and IPv6 traffic. A valid SSL or TLS session is required to exploit this vulnerability.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-11734

    Last Modified: 21 Nov 2024

    In e107 v2.1.7, output without filtering results in XSS.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2018-19578

    Last Modified: 21 Nov 2024

    GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.

    Published: 10 Jul 2019
    5.4
    Medium

    CVE-2018-19579

    Last Modified: 21 Nov 2024

    GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2018-19584

    Last Modified: 21 Nov 2024

    GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerability that allows authenticated, but unauthorized, users to view members and milestone details of private groups.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2018-19581

    Last Modified: 21 Nov 2024

    GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

    Published: 10 Jul 2019
    4.3
    Medium

    CVE-2018-19582

    Last Modified: 21 Nov 2024

    GitLab EE, versions 11.4 before 11.4.8 and 11.5 before 11.5.1, is affected by an insecure direct object reference vulnerability that permits an unauthorized user to publish the draft merge request comments of another user.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2018-19583

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-13122

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix.

    Published: 10 Jul 2019