CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-3578

    Last Modified: 30 Jun 2025

    MyBB 1.8.19 has XSS in the resetpassword function.

    Published: 6 Jun 2019
    5.3
    Medium

    CVE-2019-3579

    Last Modified: 30 Jun 2025

    MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.

    Published: 6 Jun 2019
    7.5
    High

    CVE-2019-6451

    Last Modified: 21 Nov 2024

    On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-6452

    Last Modified: 21 Nov 2024

    Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-6989

    Last Modified: 21 Nov 2024

    TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-9929

    Last Modified: 21 Nov 2024

    Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.

    Published: 6 Jun 2019
    7.5
    High

    CVE-2019-12291

    Last Modified: 21 Nov 2024

    HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix matching in a policy can be deleted by a token using that policy even with default deny settings configured.

    Published: 6 Jun 2019
    9.8
    Critical

    CVE-2019-12135

    Last Modified: 21 Nov 2024

    An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

    Published: 6 Jun 2019
    6.5
    Medium

    CVE-2019-7215

    Last Modified: 21 Nov 2024

    Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2019-7220

    Last Modified: 21 Nov 2024

    X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.

    Published: 6 Jun 2019
    7.8
    High

    CVE-2019-7311

    Last Modified: 21 Nov 2024

    An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being discoverable by a local attacker, and usable to gain administrative access to the victim's router. The admin password is stored in base64 cleartext in an "admin-auth" cookie. An attacker sniffing the network at the time of login could acquire the router's admin password. Alternatively, gaining physical access to the victim's computer soon after an administrative login could result in compromise.

    Published: 6 Jun 2019
    5.4
    Medium

    CVE-2019-7552

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2019-7554

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-12274

    Last Modified: 21 Nov 2024

    In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally allow posting certain data to the cloud. The problem is that a user could choose to post a sensitive file such as /root/.kube/config or /var/lib/rancher/management-state/cred/kubeconfig-system.yaml.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-12303

    Last Modified: 21 Nov 2024

    In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.

    Published: 6 Jun 2019
    4.7
    Medium

    CVE-2019-12732

    Last Modified: 21 Nov 2024

    The Chartkick gem through 3.1.0 for Ruby allows XSS.

    Published: 6 Jun 2019
    5.5
    Medium

    CVE-2019-5219

    Last Modified: 21 Nov 2024

    There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0.0.181(C00E87R2P20T8). An attacker tricks the user into installing a malicious application, which makes multiple processes operate the same resource at the same time. Successful exploit could cause a denial of service condition.

    Published: 6 Jun 2019
    6.4
    Medium

    CVE-2019-5295

    Last Modified: 21 Nov 2024

    Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass vulnerability. Due to improper authorization implementation logic, attackers can bypass certain authorization scopes of smart phones by performing specific operations. This vulnerability can be exploited to perform operations beyond the scope of authorization.

    Published: 6 Jun 2019
    5.5
    Medium

    CVE-2019-5305

    Last Modified: 21 Nov 2024

    The image processing module of some Huawei Mate 10 smartphones versions before ALP-L29 9.0.0.159(C185) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which could trigger double free and cause a system crash.

    Published: 6 Jun 2019
    7
    High

    CVE-2019-5216

    Last Modified: 21 Nov 2024

    There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C00E156R2P14T8), Honor 10 smartphones versions earlier than Columbia-AL10B 9.0.0.156(C00E156R1P20T8) and Honor Play smartphones versions earlier than Cornell-AL00A 9.0.0.156(C00E156R1P13T8). An attacker tricks the user into installing a malicious application, which makes multiple processes to operate the same variate at the same time. Successful exploit could cause execution of malicious code.

    Published: 6 Jun 2019
    7.8
    High

    CVE-2019-5242

    Last Modified: 21 Nov 2024

    There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to execute malicious code and read/write memory.

    Published: 6 Jun 2019
    7.8
    High

    CVE-2019-5241

    Last Modified: 21 Nov 2024

    There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.

    Published: 6 Jun 2019
    5.5
    Medium

    CVE-2019-5214

    Last Modified: 21 Nov 2024

    There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0.0.167(C00E85R2P20T8). An attacker tricks the user into installing a malicious application, which make the software to reference memory after it has been freed. Successful exploit could cause a denial of service condition.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-11080

    Last Modified: 21 Nov 2024

    Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-12134

    Last Modified: 21 Nov 2024

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a value (provided by a low-privileged user in a contact form field) that is mishandled in a CSV export.

    Published: 6 Jun 2019
    5.5
    Medium

    CVE-2019-4220

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2019-4201

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 159122.

    Published: 6 Jun 2019
    8.3
    High

    CVE-2019-4185

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975.

    Published: 6 Jun 2019
    4.3
    Medium

    CVE-2019-4056

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.

    Published: 6 Jun 2019
    2.1
    Low

    CVE-2019-4048

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.

    Published: 6 Jun 2019
    6.5
    Medium

    CVE-2018-2028

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.

    Published: 6 Jun 2019
    5.4
    Medium

    CVE-2019-7553

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.

    Published: 6 Jun 2019
    7.8
    High

    CVE-2019-25044

    Last Modified: 21 Nov 2024

    The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.

    Published: 6 Jun 2019
    9.8
    Critical

    CVE-2019-12929

    Last Modified: 21 Nov 2024

    The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue

    Published: 6 Jun 2019
    9.8
    Critical

    CVE-2018-10171

    Last Modified: 21 Nov 2024

    Kromtech MacKeeper 3.20.4 suffers from a root privilege escalation vulnerability through its `com.mackeeper.AdwareAnalyzer.AdwareAnalyzerPrivilegedHelper` component. The AdwareAnalzyerPrivilegedHelper tool implements an XPC service that allows an unprivileged application to connect and execute shell scripts as the root user.

    Published: 5 Jun 2019
    5.3
    Medium

    CVE-2017-15123

    Last Modified: 21 Nov 2024

    A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.

    Published: 5 Jun 2019
    9
    Critical

    CVE-2019-7671

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-7672

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.

    Published: 5 Jun 2019
    8.5
    High

    CVE-2019-12494

    Last Modified: 21 Nov 2024

    In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-8385

    Last Modified: 21 Nov 2024

    An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop.Service.exe and ThomsonReuters.Desktop.exe allows a remote attacker to list or enumerate sensitive contents of files via a \.. to port 6677. Additionally, this could allow for privilege escalation by dumping the affected machine's SAM and SYSTEM database files, as well as remote code execution.

    Published: 5 Jun 2019
    8
    High

    CVE-2019-9156

    Last Modified: 21 Nov 2024

    Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.

    Published: 5 Jun 2019
    5.7
    Medium

    CVE-2019-9157

    Last Modified: 21 Nov 2024

    Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.

    Published: 5 Jun 2019
    5.7
    Medium

    CVE-2019-9158

    Last Modified: 21 Nov 2024

    Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-6800

    Last Modified: 21 Nov 2024

    In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-11988

    Last Modified: 21 Nov 2024

    A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

    Published: 5 Jun 2019
    5.4
    Medium

    CVE-2019-11226

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-9187

    Last Modified: 21 Nov 2024

    ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.

    Published: 5 Jun 2019
    7.8
    High

    CVE-2019-11987

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege.

    Published: 5 Jun 2019
    5.1
    Medium

    CVE-2019-5394

    Last Modified: 21 Nov 2024

    The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-12196

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

    Published: 5 Jun 2019