CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-11729

    Last Modified: 25 Nov 2025

    Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    5.3
    Medium

    CVE-2019-11717

    Last Modified: 25 Nov 2025

    A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2019-11730

    Last Modified: 21 Nov 2024

    A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    7.5
    High

    CVE-2019-11719

    Last Modified: 25 Nov 2025

    When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-13132

    Last Modified: 21 Nov 2024

    In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.

    Published: 10 Jul 2019
    4.8
    Medium

    CVE-2018-17147

    Last Modified: 21 Nov 2024

    Nagios XI before 5.5.4 has XSS in the auto login admin management page.

    Published: 10 Jul 2019
    8.3
    High

    CVE-2019-9811

    Last Modified: 21 Nov 2024

    As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-11709

    Last Modified: 25 Nov 2025

    Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-11713

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    6.5
    Medium

    CVE-2019-13504

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2017-12652

    Last Modified: 9 Jun 2025

    libpng before 1.6.32 does not properly check the length of chunks against the user limit.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-11711

    Last Modified: 25 Nov 2025

    When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    8.8
    High

    CVE-2019-11712

    Last Modified: 25 Nov 2025

    POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    6.1
    Medium

    CVE-2019-11715

    Last Modified: 25 Nov 2025

    Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

    Published: 10 Jul 2019
    9.8
    Critical

    CVE-2019-13478

    Last Modified: 21 Nov 2024

    The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.

    Published: 9 Jul 2019
    8.8
    High

    CVE-2019-13475

    Last Modified: 21 Nov 2024

    In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially crafted URL. Based on the available command-line arguments of the software, one can simply inject -exec to execute arbitrary commands. The additional arguments -hideterm and -exitwhendone in the payload make the attack less visible.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-13472

    Last Modified: 21 Nov 2024

    PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-13470

    Last Modified: 21 Nov 2024

    MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

    Published: 9 Jul 2019
    5.3
    Medium

    CVE-2019-9150

    Last Modified: 21 Nov 2024

    Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key was imported.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-9149

    Last Modified: 21 Nov 2024

    Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelope, assuming the private key password is cached. A second vulnerability allows an attacker to decrypt an arbitrary message when the GnuPG backend is used in Mailvelope.

    Published: 9 Jul 2019
    4.3
    Medium

    CVE-2019-9148

    Last Modified: 21 Nov 2024

    Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a valid self-certification. Keys that are obviously invalid are not rejected during import. An attacker that is able to get a victim to import a manipulated key could claim to have signed a message that originates from another person.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-13380

    Last Modified: 21 Nov 2024

    KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-11512

    Last Modified: 21 Nov 2024

    Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-13277

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard functionality, giving this attacker the ability to change configuration values, potentially leading to a denial of service. The request can be made on the local intranet or remotely if remote administration is enabled.

    Published: 9 Jul 2019
    4.3
    Medium

    CVE-2019-9147

    Last Modified: 21 Nov 2024

    Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended to be accessible from web applications, the browser's extension isolation mechanisms are disabled (web_accessible_resources). Mailvelope implements additional measures to prevent web applications from directly embedding the settings page, but this mechanism can be bypassed.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-13337

    Last Modified: 21 Nov 2024

    In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the backend. The website can then be browsed as if no basic authentication is required.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-13338

    Last Modified: 21 Nov 2024

    In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.

    Published: 9 Jul 2019
    8.8
    High

    CVE-2019-13280

    Last Modified: 21 Nov 2024

    TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an error message to the user about failure to resolve a hostname during a ping or traceroute attempt. This allows an authenticated user to execute arbitrary code. The exploit can be exercised on the local intranet or remotely if remote administration is enabled.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-11991

    Last Modified: 21 Nov 2024

    HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any managed 3PAR arrays.

    Published: 9 Jul 2019
    —
    Unknown

    CVE-2019-5044

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-13464

    Last Modified: 21 Nov 2024

    An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

    Published: 9 Jul 2019
    5.4
    Medium

    CVE-2019-13070

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Recipient page, the embedded code will be executed in the browser of the victim.

    Published: 9 Jul 2019
    5.3
    Medium

    CVE-2019-13146

    Last Modified: 21 Nov 2024

    The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).

    Published: 9 Jul 2019
    5.5
    Medium

    CVE-2019-13142

    Last Modified: 21 Nov 2024

    The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-13461

    Last Modified: 21 Nov 2024

    In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-3950

    Last Modified: 21 Nov 2024

    Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-3949

    Last Modified: 21 Nov 2024

    Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-8920

    Last Modified: 21 Nov 2024

    iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-11020

    Last Modified: 21 Nov 2024

    Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-13397

    Last Modified: 21 Nov 2024

    Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-11019

    Last Modified: 21 Nov 2024

    Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs.

    Published: 9 Jul 2019
    8.1
    High

    CVE-2019-12782

    Last Modified: 21 Nov 2024

    An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards of another user in the application by spoofing GUIDs in pinboard update requests, effectively deleting them.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-12748

    Last Modified: 21 Nov 2024

    TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.

    Published: 9 Jul 2019
    8.8
    High

    CVE-2019-12747

    Last Modified: 21 Nov 2024

    TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-11890

    Last Modified: 21 Nov 2024

    Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired or Wi-Fi LAN.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-11889

    Last Modified: 21 Nov 2024

    Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page over HbbTV.

    Published: 9 Jul 2019
    5.9
    Medium

    CVE-2018-14833

    Last Modified: 21 Nov 2024

    Intuit Lacerte 2017 has Incorrect Access Control.

    Published: 9 Jul 2019
    5.5
    Medium

    CVE-2018-15738

    Last Modified: 21 Nov 2024

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000205F.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-13450

    Last Modified: 21 Nov 2024

    In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-13449

    Last Modified: 21 Nov 2024

    In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.

    Published: 9 Jul 2019