CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-13279

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for the setup wizard, allowing an unauthenticated user to execute arbitrary code. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-13278

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-13276

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by providing a sufficiently long query string when POSTing to any valid cgi, txt, asp, or js file. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2019-12470

    Last Modified: 21 Nov 2024

    Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2018-19580

    Last Modified: 21 Nov 2024

    All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2019-12469

    Last Modified: 21 Nov 2024

    MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    7.7
    High

    CVE-2018-19571

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

    Published: 10 Jul 2019
    5.4
    Medium

    CVE-2018-19574

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-12474

    Last Modified: 21 Nov 2024

    Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2018-19569

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-12472

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypass the limits on IP range blocks ($wgBlockCIDRLimit) by using the API. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    4.3
    Medium

    CVE-2018-19575

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 10.1 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an insecure direct object reference issue that allows a user to make comments on a locked issue.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-12471

    Last Modified: 21 Nov 2024

    Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-12473

    Last Modified: 21 Nov 2024

    Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    8.1
    High

    CVE-2018-19576

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2018-10531

    Last Modified: 21 Nov 2024

    An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.

    Published: 10 Jul 2019
    5.9
    Medium

    CVE-2018-19572

    Last Modified: 21 Nov 2024

    GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-12466

    Last Modified: 21 Nov 2024

    Wikimedia MediaWiki through 1.32.1 allows CSRF.

    Published: 10 Jul 2019
    5.4
    Medium

    CVE-2018-19570

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.

    Published: 10 Jul 2019
    5.4
    Medium

    CVE-2018-19573

    Last Modified: 21 Nov 2024

    GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2018-19577

    Last Modified: 21 Nov 2024

    Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-12468

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2018-19496

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2018-19495

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.

    Published: 10 Jul 2019
    4.3
    Medium

    CVE-2018-19494

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-12467

    Last Modified: 21 Nov 2024

    MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-19493

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2017-7189

    Last Modified: 21 Nov 2024

    main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later truncated to 127.0.0.1:80. This behavior has a security risk if the explicitly provided port number (i.e., 443 in this example) is hardcoded into an application as a security policy, but the hostname argument (i.e., 127.0.0.1:80 in this example) is obtained from untrusted input.

    Published: 10 Jul 2019
    4.9
    Medium

    CVE-2018-14831

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2017-6217

    Last Modified: 21 Nov 2024

    paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-10653

    Last Modified: 21 Nov 2024

    An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-12724

    Last Modified: 21 Nov 2024

    An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.

    Published: 10 Jul 2019
    5.9
    Medium

    CVE-2019-13240

    Last Modified: 21 Nov 2024

    An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-13071

    Last Modified: 21 Nov 2024

    CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-13396

    Last Modified: 21 Nov 2024

    FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2018-20851

    Last Modified: 21 Nov 2024

    Helpy before 2.2.0 allows agents to edit admins.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2018-14496

    Last Modified: 21 Nov 2024

    Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2018-14495

    Last Modified: 21 Nov 2024

    Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not cause a web server crash or have any other affect on it's performance

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2018-14494

    Last Modified: 21 Nov 2024

    Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not apply to any current or recent Vivotek hardware or firmware

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-12723

    Last Modified: 21 Nov 2024

    An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-10122

    Last Modified: 21 Nov 2024

    eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTTP-Server 2.0 component, aka HMCCU-179. This may lead to remote code execution.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-10121

    Last Modified: 21 Nov 2024

    eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via the user authentication dialogue, aka HMCCU-153. This leads to automatic login as admin.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-10119

    Last Modified: 21 Nov 2024

    eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID via an invalid login attempt to the RemoteApi account, aka HMCCU-154. This leads to automatic login as admin.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-10120

    Last Modified: 21 Nov 2024

    On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAutoLogin) can be achieved by continuing to use a session ID after a logout, aka HMCCU-154.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2018-12628

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-12627

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-12626

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-12625

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-12623

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2018-12622

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.

    Published: 10 Jul 2019