CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2018-16594

    Last Modified: 21 Nov 2024

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-16595

    Last Modified: 21 Nov 2024

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-12890

    Last Modified: 21 Nov 2024

    RedwoodHQ 2.5.5 does not require any authentication for database operations, which allows remote attackers to create admin users via a con.automationframework users insert_one call.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-16613

    Last Modified: 21 Nov 2024

    An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-16618

    Last Modified: 21 Nov 2024

    VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.

    Published: 19 Jun 2019
    6.1
    Medium

    CVE-2018-17079

    Last Modified: 21 Nov 2024

    An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17374

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17381

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17386

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

    Published: 19 Jun 2019
    8.8
    High

    CVE-2018-17387

    Last Modified: 21 Nov 2024

    CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.

    Published: 19 Jun 2019
    6.1
    Medium

    CVE-2019-9763

    Last Modified: 21 Nov 2024

    An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17388

    Last Modified: 21 Nov 2024

    SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.

    Published: 19 Jun 2019
    8.8
    High

    CVE-2018-17389

    Last Modified: 21 Nov 2024

    CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-11233

    Last Modified: 21 Nov 2024

    EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the auth/main/asp/check_user_login_info.aspx URI, and then reading the response, as demonstrated by the KW_EMAIL or KW_TEL field.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-11232

    Last Modified: 21 Nov 2024

    EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17393

    Last Modified: 21 Nov 2024

    SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17398

    Last Modified: 21 Nov 2024

    SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17399

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.

    Published: 19 Jun 2019
    4.8
    Medium

    CVE-2018-17423

    Last Modified: 21 Nov 2024

    An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17840

    Last Modified: 21 Nov 2024

    SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-15506

    Last Modified: 21 Nov 2024

    In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running BubbleUPnP, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack the cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17841

    Last Modified: 21 Nov 2024

    SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.

    Published: 19 Jun 2019
    5.4
    Medium

    CVE-2019-11649

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability in Micro Focus Fortify Software Security Center Server, versions 17.2, 18.1, 18.2, has been identified in Micro Focus Software Security Center. The vulnerability could be exploited to execute JavaScript code in user’s browser. The vulnerability could be exploited to execute JavaScript code in user’s browser.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-17842

    Last Modified: 21 Nov 2024

    SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.

    Published: 19 Jun 2019
    9.9
    Critical

    CVE-2018-18406

    Last Modified: 21 Nov 2024

    An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-18425

    Last Modified: 21 Nov 2024

    The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency. (Increasing the total supply by using 'doAirdrop' ignores the hard cap written in the contract and devalues the token.)

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-6114

    Last Modified: 21 Nov 2024

    An issue was discovered in Corel PaintShop Pro 2019 21.0.0.119. An integer overflow in the jp2 parsing library allows an attacker to overwrite memory and to execute arbitrary code.

    Published: 19 Jun 2019
    4.8
    Medium

    CVE-2019-9701

    Last Modified: 21 Nov 2024

    DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-18471

    Last Modified: 21 Nov 2024

    /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-18472

    Last Modified: 21 Nov 2024

    Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter. It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,

    Published: 19 Jun 2019
    6.6
    Medium

    CVE-2019-12491

    Last Modified: 21 Nov 2024

    OnApp before 5.0.0-88, 5.5.0-93, and 6.0.0-196 allows an attacker to run arbitrary commands with root privileges on servers managed by OnApp for XEN/KVM hypervisors. To exploit the vulnerability an attacker has to have control of a single server on a given cloud (e.g. by renting one). From the source server, the attacker can craft any command and trigger the OnApp platform to execute that command with root privileges on a target server.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-18757

    Last Modified: 21 Nov 2024

    Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-18863

    Last Modified: 21 Nov 2024

    NGA ResourceLink 20.0.2.1 allows local file inclusion.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2018-18758

    Last Modified: 21 Nov 2024

    Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-19878

    Last Modified: 21 Nov 2024

    An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-6972

    Last Modified: 21 Nov 2024

    An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy decoding. Also, the username is cleartext, and the password is hashed with the MD5 algorithm (after decoding of the URL encoded string with base64).

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-6971

    Last Modified: 21 Nov 2024

    An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-10257

    Last Modified: 21 Nov 2024

    Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash notation) to access files or directories that are elsewhere on the system. Through this vulnerability it is possible to read the application's java sources from /WEB-INF/classes/*.class

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-4385

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive information as well as vSnap. IBM X-Force ID: 162173.

    Published: 19 Jun 2019
    4.3
    Medium

    CVE-2019-4384

    Last Modified: 21 Nov 2024

    IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.

    Published: 19 Jun 2019
    8
    High

    CVE-2019-4364

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to execute arbirary commands on the system. IBM X-Force ID: 161680.

    Published: 19 Jun 2019
    5.4
    Medium

    CVE-2019-4303

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160949.

    Published: 19 Jun 2019
    4.3
    Medium

    CVE-2017-1107

    Last Modified: 21 Nov 2024

    IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-13135

    Last Modified: 21 Nov 2024

    ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-12435

    Last Modified: 21 Nov 2024

    Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-10171

    Last Modified: 21 Nov 2024

    It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-10746

    Last Modified: 21 Nov 2024

    mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

    Published: 19 Jun 2019
    5.9
    Medium

    CVE-2019-6471

    Last Modified: 21 Nov 2024

    A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-13137

    Last Modified: 21 Nov 2024

    ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.

    Published: 19 Jun 2019
    5.4
    Medium

    CVE-2018-17146

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.

    Published: 19 Jun 2019