CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-7277

    Last Modified: 21 Nov 2024

    Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure.

    Published: 1 Jul 2019
    6.5
    Medium

    CVE-2019-7278

    Last Modified: 21 Nov 2024

    Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.

    Published: 1 Jul 2019
    3.3
    Low

    CVE-2019-3962

    Last Modified: 21 Nov 2024

    Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.

    Published: 1 Jul 2019
    7.3
    High

    CVE-2019-7279

    Last Modified: 21 Nov 2024

    Optergy Proton/Enterprise devices have Hard-coded Credentials.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-7280

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.

    Published: 1 Jul 2019
    6.1
    Medium

    CVE-2019-1578

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.

    Published: 1 Jul 2019
    6.3
    Medium

    CVE-2019-1577

    Last Modified: 21 Nov 2024

    Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-7281

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-7666

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-7667

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker can use brute force to identify the database backup file name. A malicious actor can exploit this issue to download the database file and disclose login information, which can allow the attacker to bypass authentication and have full access to the system.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-7668

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir devices have Default Credentials.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-7669

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-13024

    Last Modified: 21 Nov 2024

    Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary command into the database, and execute it by calling the vulnerable page www/include/configuration/configGenerate/xml/generateFiles.php (which passes the inserted value to the database to shell_exec without sanitizing it, allowing one to execute system arbitrary commands).

    Published: 1 Jul 2019
    7.2
    High

    CVE-2019-7670

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-12826

    Last Modified: 21 Nov 2024

    A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.

    Published: 1 Jul 2019
    5.4
    Medium

    CVE-2016-5236

    Last Modified: 21 Nov 2024

    Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when creating a new user, account or signature.

    Published: 1 Jul 2019
    6.1
    Medium

    CVE-2016-5235

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-13131

    Last Modified: 21 Nov 2024

    Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.

    Published: 1 Jul 2019
    5.4
    Medium

    CVE-2019-4410

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162657.

    Published: 1 Jul 2019
    6.5
    Medium

    CVE-2019-4386

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a function that would cause the server to crash. IBM X-Force ID: 162714.

    Published: 1 Jul 2019
    6.7
    Medium

    CVE-2019-4383

    Last Modified: 21 Nov 2024

    When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165.

    Published: 1 Jul 2019
    6.7
    Medium

    CVE-2019-4357

    Last Modified: 21 Nov 2024

    When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,

    Published: 1 Jul 2019
    5.3
    Medium

    CVE-2019-4337

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-4336

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.

    Published: 1 Jul 2019
    7.8
    High

    CVE-2019-4322

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 161202.

    Published: 1 Jul 2019
    5.5
    Medium

    CVE-2019-4299

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765.

    Published: 1 Jul 2019
    7.1
    High

    CVE-2019-4298

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764.

    Published: 1 Jul 2019
    5.4
    Medium

    CVE-2019-4297

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761.

    Published: 1 Jul 2019
    3.3
    Low

    CVE-2019-4296

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759.

    Published: 1 Jul 2019
    4.9
    Medium

    CVE-2019-4295

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758.

    Published: 1 Jul 2019
    5.4
    Medium

    CVE-2019-4237

    Last Modified: 21 Nov 2024

    A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.

    Published: 1 Jul 2019
    7.8
    High

    CVE-2019-4154

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 158519.

    Published: 1 Jul 2019
    5.9
    Medium

    CVE-2019-4102

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158092.

    Published: 1 Jul 2019
    5.5
    Medium

    CVE-2019-4101

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of service. Users that have both EXECUTE on PD_GET_DIAG_HIST and access to the diagnostic directory on the DB2 server can cause the instance to crash. IBM X-Force ID: 158091.

    Published: 1 Jul 2019
    6.7
    Medium

    CVE-2019-4057

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user with access to the DB2 instance account to leverage a fenced execution process to execute arbitrary code as root. IBM X-Force ID: 156567.

    Published: 1 Jul 2019
    7.5
    High

    CVE-2019-13129

    Last Modified: 21 Nov 2024

    On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.

    Published: 1 Jul 2019
    8.8
    High

    CVE-2019-13128

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.

    Published: 1 Jul 2019
    6.1
    Medium

    CVE-2019-13127

    Last Modified: 21 Nov 2024

    An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.

    Published: 1 Jul 2019
    7.8
    High

    CVE-2019-13125

    Last Modified: 21 Nov 2024

    HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.

    Published: 1 Jul 2019
    8.1
    High

    CVE-2019-10137

    Last Modified: 21 Nov 2024

    A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context of the httpd process.

    Published: 1 Jul 2019
    5.3
    Medium

    CVE-2019-12781

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.

    Published: 1 Jul 2019
    7.8
    High

    CVE-2019-18276

    Last Modified: 9 Jun 2025

    An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-7276

    Last Modified: 21 Nov 2024

    Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

    Published: 1 Jul 2019
    4.3
    Medium

    CVE-2019-10136

    Last Modified: 21 Nov 2024

    It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

    Published: 1 Jul 2019
    6.1
    Medium

    CVE-2019-12970

    Last Modified: 21 Nov 2024

    XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element.

    Published: 1 Jul 2019
    9.8
    Critical

    CVE-2019-13107

    Last Modified: 21 Nov 2024

    Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c

    Published: 30 Jun 2019
    6.1
    Medium

    CVE-2018-20849

    Last Modified: 21 Nov 2024

    Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.

    Published: 30 Jun 2019
    8.8
    High

    CVE-2018-20848

    Last Modified: 21 Nov 2024

    Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.

    Published: 30 Jun 2019
    9.8
    Critical

    CVE-2019-13086

    Last Modified: 21 Nov 2024

    core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

    Published: 30 Jun 2019
    7.8
    High

    CVE-2019-13085

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.

    Published: 30 Jun 2019