CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-1619

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper session management on affected DCNM software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.

    Published: 27 Jun 2019
    6.5
    Medium

    CVE-2019-10177

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.

    Published: 27 Jun 2019
    7.5
    High

    CVE-2019-1020001

    Last Modified: 21 Nov 2024

    yard before 0.9.20 allows path traversal.

    Published: 27 Jun 2019
    9.8
    Critical

    CVE-2019-13224

    Last Modified: 21 Nov 2024

    A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

    Published: 27 Jun 2019
    9.8
    Critical

    CVE-2019-9827

    Last Modified: 21 Nov 2024

    Hawt Hawtio through 2.5.0 is vulnerable to SSRF, allowing a remote attacker to trigger an HTTP request from an affected server to an arbitrary host via the initial /proxy/ substring of a URI.

    Published: 27 Jun 2019
    6.5
    Medium

    CVE-2019-13225

    Last Modified: 21 Nov 2024

    A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.

    Published: 27 Jun 2019
    9.8
    Critical

    CVE-2019-9039

    Last Modified: 21 Nov 2024

    In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with CPU-intensive operations they may have been able to cause increased resource usage and denial of service conditions. The _all_docs endpoint is not required for Couchbase Mobile replication and external access to this REST endpoint has been blocked to mitigate this issue. This issue has been fixed in versions 2.5.0 and 2.1.3.

    Published: 26 Jun 2019
    7.5
    High

    CVE-2019-10154

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

    Published: 26 Jun 2019
    3.7
    Low

    CVE-2019-10134

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

    Published: 26 Jun 2019
    3.1
    Low

    CVE-2019-10133

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

    Published: 26 Jun 2019
    —
    Unknown

    CVE-2019-12983

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11884. Reason: This candidate is a reservation duplicate of CVE-2019-11884. Notes: All CVE users should reference CVE-2019-11884 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jun 2019
    6.5
    Medium

    CVE-2019-12982

    Last Modified: 21 Nov 2024

    Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in libutil.a. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted SWF file.

    Published: 26 Jun 2019
    8.8
    High

    CVE-2019-12981

    Last Modified: 21 Nov 2024

    Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.c.

    Published: 26 Jun 2019
    6.5
    Medium

    CVE-2019-12980

    Last Modified: 21 Nov 2024

    In Ming (aka libming) 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the SWFInput_readSBits function in blocks/input.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

    Published: 26 Jun 2019
    6.5
    Medium

    CVE-2019-11583

    Last Modified: 21 Nov 2024

    The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".

    Published: 26 Jun 2019
    7.5
    High

    CVE-2019-3569

    Last Modified: 21 Nov 2024

    HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

    Published: 26 Jun 2019
    7.8
    High

    CVE-2019-4241

    Last Modified: 21 Nov 2024

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 159467.

    Published: 26 Jun 2019
    7.5
    High

    CVE-2019-4235

    Last Modified: 21 Nov 2024

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.

    Published: 26 Jun 2019
    4.3
    Medium

    CVE-2019-4234

    Last Modified: 21 Nov 2024

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: 159416.

    Published: 26 Jun 2019
    4.4
    Medium

    CVE-2019-4225

    Last Modified: 21 Nov 2024

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.

    Published: 26 Jun 2019
    8.8
    High

    CVE-2019-4224

    Last Modified: 21 Nov 2024

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 159240.

    Published: 26 Jun 2019
    7.5
    High

    CVE-2019-6169

    Last Modified: 21 Nov 2024

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.

    Published: 26 Jun 2019
    9.8
    Critical

    CVE-2019-6168

    Last Modified: 21 Nov 2024

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

    Published: 26 Jun 2019
    9.8
    Critical

    CVE-2019-6167

    Last Modified: 21 Nov 2024

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.

    Published: 26 Jun 2019
    8.8
    High

    CVE-2019-6166

    Last Modified: 21 Nov 2024

    A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-6163

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations.

    Published: 26 Jun 2019
    7.3
    High

    CVE-2019-11272

    Last Modified: 12 Sept 2025

    Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

    Published: 26 Jun 2019
    5.3
    Medium

    CVE-2019-12968

    Last Modified: 21 Nov 2024

    A vulnerability was found in the Sonic Robo Blast 2 (SRB2) plugin (EP_Versions 9 to 11 inclusive) distributed with Doomseeker 1.1 and 1.2. Affected plugin versions did not discard IP packets with an unnaturally long response length from a Sonic Robo Blast 2 master server, allowing a remote attacker to cause a potential crash / denial of service in Doomseeker. The issue has been remediated in the Doomseeker 1.3 release with source code patches to the SRB2 plugin.

    Published: 26 Jun 2019
    9.8
    Critical

    CVE-2019-12966

    Last Modified: 21 Nov 2024

    FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.

    Published: 26 Jun 2019
    —
    Unknown

    CVE-2019-12888

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12887. Reason: This candidate is a reservation duplicate of CVE-2019-12887. Notes: All CVE users should reference CVE-2019-12887 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-12973

    Last Modified: 21 Nov 2024

    In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-12975

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-12984

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target() in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious user-mode program that omits certain NFC attributes, leading to denial of service.

    Published: 26 Jun 2019
    6.5
    Medium

    CVE-2018-20846

    Last Modified: 21 Nov 2024

    Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

    Published: 26 Jun 2019
    8.8
    High

    CVE-2018-20847

    Last Modified: 21 Nov 2024

    An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-12974

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in the function ReadPANGOImage in coders/pango.c and the function ReadVIDImage in coders/vid.c in ImageMagick 7.0.8-34 allows remote attackers to cause a denial of service via a crafted image.

    Published: 26 Jun 2019
    7.8
    High

    CVE-2019-12977

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the WriteJP2Image function in coders/jp2.c.

    Published: 26 Jun 2019
    7.8
    High

    CVE-2019-12978

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c.

    Published: 26 Jun 2019
    7.8
    High

    CVE-2019-12979

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.

    Published: 26 Jun 2019
    6.5
    Medium

    CVE-2018-20845

    Last Modified: 21 Nov 2024

    Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

    Published: 26 Jun 2019
    5.5
    Medium

    CVE-2019-12976

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.

    Published: 26 Jun 2019
    7.8
    High

    CVE-2019-12280

    Last Modified: 21 Nov 2024

    PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.

    Published: 25 Jun 2019
    6.1
    Medium

    CVE-2019-3961

    Last Modified: 21 Nov 2024

    Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a users browser session.

    Published: 25 Jun 2019
    5.3
    Medium

    CVE-2019-9836

    Last Modified: 21 Nov 2024

    Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.

    Published: 25 Jun 2019
    7.8
    High

    CVE-2019-6329

    Last Modified: 21 Nov 2024

    HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.

    Published: 25 Jun 2019
    7.8
    High

    CVE-2019-6328

    Last Modified: 21 Nov 2024

    HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.

    Published: 25 Jun 2019
    5.3
    Medium

    CVE-2019-4382

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the system users using specially crafted HTTP requests. IBM X-Force ID: 162162.

    Published: 25 Jun 2019
    4.3
    Medium

    CVE-2019-4377

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in further attacks against the system. IBM X-Force ID: 162803.

    Published: 25 Jun 2019
    5.4
    Medium

    CVE-2019-4158

    Last Modified: 21 Nov 2024

    IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the exposure of resources or functionality to unintended actors. IBM X-Force ID: 158574.

    Published: 25 Jun 2019
    6.1
    Medium

    CVE-2019-4157

    Last Modified: 21 Nov 2024

    IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.

    Published: 25 Jun 2019