CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2019-3410

    Last Modified: 21 Nov 2024

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this vulnerability to send unexpected requests to the server through the affected client.

    Published: 11 Jun 2019
    9
    Critical

    CVE-2019-3409

    Last Modified: 21 Nov 2024

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.

    Published: 11 Jun 2019
    6.1
    Medium

    CVE-2019-12766

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.

    Published: 11 Jun 2019
    9.8
    Critical

    CVE-2019-12765

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.

    Published: 11 Jun 2019
    6.5
    Medium

    CVE-2019-12764

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.

    Published: 11 Jun 2019
    3.7
    Low

    CVE-2019-11334

    Last Modified: 21 Nov 2024

    An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers to access resources (that are not otherwise accessible without proper authentication) via capture-replay. Physically proximate attackers can use this information to unlock unauthorized Tzumi Electronics Klic Smart Padlock Model 5686 Firmware 6.2.

    Published: 11 Jun 2019
    9.8
    Critical

    CVE-2018-11801

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

    Published: 11 Jun 2019
    9.8
    Critical

    CVE-2018-11800

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

    Published: 11 Jun 2019
    6.6
    Medium

    CVE-2019-12794

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host organization of an instance creates organization admins. An organization admin could set a password manually for the site admin or simply use the API key of the site admin to impersonate them. The potential for abuse only occurs when the host organization creates lower-privilege organization admins instead of the usual site admins. Also, only organization admins of the same organization as the site admin could abuse this.

    Published: 11 Jun 2019
    4.7
    Medium

    CVE-2019-10157

    Last Modified: 21 Nov 2024

    It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.

    Published: 11 Jun 2019
    6.5
    Medium

    CVE-2019-3875

    Last Modified: 21 Nov 2024

    A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http' or 'ldap') and hence the caller should verify the signature and possibly the certification path. Keycloak currently doesn't validate signatures on CRL, which can result in a possibility of various attacks like man-in-the-middle.

    Published: 11 Jun 2019
    8.8
    High

    CVE-2019-10338

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.

    Published: 11 Jun 2019
    8.8
    High

    CVE-2019-10339

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed users with Overall/Read access to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.

    Published: 11 Jun 2019
    4.3
    Medium

    CVE-2019-10331

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 11 Jun 2019
    4.3
    Medium

    CVE-2019-10332

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 11 Jun 2019
    4.3
    Medium

    CVE-2019-10333

    Last Modified: 21 Nov 2024

    Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances.

    Published: 11 Jun 2019
    6.5
    Medium

    CVE-2019-10334

    Last Modified: 21 Nov 2024

    Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files.

    Published: 11 Jun 2019
    6.1
    Medium

    CVE-2019-10336

    Last Modified: 21 Nov 2024

    A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this plugin.

    Published: 11 Jun 2019
    5.4
    Medium

    CVE-2019-10335

    Last Modified: 21 Nov 2024

    A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.

    Published: 11 Jun 2019
    8.1
    High

    CVE-2018-10899

    Last Modified: 21 Nov 2024

    A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.

    Published: 11 Jun 2019
    7.1
    High

    CVE-2019-12749

    Last Modified: 13 Feb 2026

    dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.

    Published: 11 Jun 2019
    7.4
    High

    CVE-2019-0136

    Last Modified: 21 Nov 2024

    Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver before version 21.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 11 Jun 2019
    8.8
    High

    CVE-2019-7845

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jun 2019
    3.3
    Low

    CVE-2019-0174

    Last Modified: 21 Nov 2024

    Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical address information disclosure via local access.

    Published: 11 Jun 2019
    6.5
    Medium

    CVE-2019-11702

    Last Modified: 21 Nov 2024

    A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

    Published: 11 Jun 2019
    7.5
    High

    CVE-2019-10337

    Last Modified: 21 Nov 2024

    An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

    Published: 11 Jun 2019
    8.8
    High

    CVE-2019-13391

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.

    Published: 11 Jun 2019
    8.8
    High

    CVE-2017-13717

    Last Modified: 21 Nov 2024

    Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credentials and pull any information that is stored on the device. In this case, a user's Wi-Fi credentials are stored in clear text on the device and can be pulled easily.

    Published: 10 Jun 2019
    8
    High

    CVE-2017-13718

    Last Modified: 21 Nov 2024

    The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings and PIN, as well as port forward and expose any internal device's port to the Internet. It was identified that the device uses custom Python code called "rodman" that allows the mobile appication to interact with the device. The APIs that are a part of this rodman Python file allow the mobile application to interact with the device using a secret, which is a uuid4 based session identifier generated by the device the first time it is set up. However, in some cases, these APIs can also use a security code. This security code is nothing but the PIN number set by the user to interact with the device when using the touch interface on the router. This allows an attacker on the Internet to interact with the router's HTTP interface when a user navigates to the attacker's website, and brute force the credentials. Also, since the device's server sets the Access-Control-Allow-Origin header to "*", an attacker can easily interact with the JSON payload returned by the device and steal sensitive information about the device.

    Published: 10 Jun 2019
    4.7
    Medium

    CVE-2019-11881

    Last Modified: 4 Dec 2024

    A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading" message.

    Published: 10 Jun 2019
    7.8
    High

    CVE-2019-12790

    Last Modified: 21 Nov 2024

    In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of missing length validation in libr/egg/egg.c.

    Published: 10 Jun 2019
    7.8
    High

    CVE-2019-12788

    Last Modified: 21 Nov 2024

    An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a buffer overflow via a crafted file.

    Published: 10 Jun 2019
    8.8
    High

    CVE-2019-12787

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.

    Published: 10 Jun 2019
    8.8
    High

    CVE-2019-12786

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.

    Published: 10 Jun 2019
    6.5
    Medium

    CVE-2019-11517

    Last Modified: 21 Nov 2024

    WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner.

    Published: 10 Jun 2019
    5.3
    Medium

    CVE-2019-9881

    Last Modified: 21 Nov 2024

    The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

    Published: 10 Jun 2019
    9.1
    Critical

    CVE-2019-9880

    Last Modified: 21 Nov 2024

    An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2019-9879

    Last Modified: 21 Nov 2024

    The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

    Published: 10 Jun 2019
    6.1
    Medium

    CVE-2019-11877

    Last Modified: 21 Nov 2024

    XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2018-20356

    Last Modified: 21 Nov 2024

    An invalid read of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2018-20355

    Last Modified: 21 Nov 2024

    An invalid write of 8 bytes due to a use-after-free vulnerability in the mg_http_free_proto_data_cgi function call in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2018-20354

    Last Modified: 21 Nov 2024

    An invalid read of 8 bytes due to a use-after-free vulnerability during a "return" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2018-20353

    Last Modified: 21 Nov 2024

    An invalid read of 8 bytes due to a use-after-free vulnerability during a "NULL test" in the mg_http_get_proto_data function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

    Published: 10 Jun 2019
    8.8
    High

    CVE-2018-20352

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution.

    Published: 10 Jun 2019
    7.5
    High

    CVE-2019-6241

    Last Modified: 21 Nov 2024

    In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be used to cause a Denial of Service attack against the broker.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2019-12780

    Last Modified: 21 Nov 2024

    The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.

    Published: 10 Jun 2019
    5.4
    Medium

    CVE-2019-3872

    Last Modified: 21 Nov 2024

    It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.

    Published: 10 Jun 2019
    6.4
    Medium

    CVE-2019-3873

    Last Modified: 21 Nov 2024

    It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

    Published: 10 Jun 2019
    9.8
    Critical

    CVE-2019-3888

    Last Modified: 21 Nov 2024

    A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

    Published: 10 Jun 2019
    4.3
    Medium

    CVE-2019-5243

    Last Modified: 21 Nov 2024

    There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.

    Published: 10 Jun 2019