CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-12276

    Last Modified: 21 Nov 2024

    A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-9189

    Last Modified: 21 Nov 2024

    Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately executed because of root code execution, not as a web server user, allowing an authenticated attacker to gain full system access.

    Published: 5 Jun 2019
    7
    High

    CVE-2019-11983

    Last Modified: 21 Nov 2024

    A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

    Published: 5 Jun 2019
    4.7
    Medium

    CVE-2019-1881

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to use a web browser and the privileges of the user to perform arbitrary actions on an affected device. For more information about CSRF attacks and potential mitigations, see Understanding Cross-Site Request Forgery Threat Vectors.

    Published: 5 Jun 2019
    5.4
    Medium

    CVE-2019-1882

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks. The vulnerability is due to improper validation of content submitted to the affected application. An attacker could exploit this vulnerability by sending requests containing malicious values to the affected system. A successful exploit could allow the attacker to conduct XSS attacks.

    Published: 5 Jun 2019
    8.3
    High

    CVE-2019-11982

    Last Modified: 21 Nov 2024

    A remote cross site scripting vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-1870

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Enterprise Chat and Email (ECE) Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web interface or allow the attacker to access sensitive browser-based information.

    Published: 5 Jun 2019
    5.3
    Medium

    CVE-2019-1872

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An attacker could exploit this vulnerability by sending malicious requests to the affected system. A successful exploit could allow the attacker to send arbitrary network requests sourced from the affected system.

    Published: 5 Jun 2019
    4.4
    Medium

    CVE-2019-1880

    Last Modified: 21 Nov 2024

    A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.

    Published: 5 Jun 2019
    8.6
    High

    CVE-2019-1845

    Last Modified: 21 Nov 2024

    A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to authenticate, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient controls for specific memory operations. An attacker could exploit this vulnerability by sending a malformed Extensible Messaging and Presence Protocol (XMPP) authentication request to an affected system. A successful exploit could allow the attacker to cause an unexpected restart of the authentication service, preventing users from successfully authenticating. Exploitation of this vulnerability does not impact users who were authenticated prior to an attack.

    Published: 5 Jun 2019
    7.2
    High

    CVE-2019-1861

    Last Modified: 21 Nov 2024

    A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system using administrator privileges and uploading an arbitrary file. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-1868

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending a malicious request to an affected device. A successful exploit could allow the attacker to access sensitive system information.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-12554

    Last Modified: 21 Nov 2024

    In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.

    Published: 5 Jun 2019
    10
    Critical

    CVE-2019-9548

    Last Modified: 21 Nov 2024

    Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-12553

    Last Modified: 21 Nov 2024

    In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the StrCat function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

    Published: 5 Jun 2019
    5.4
    Medium

    CVE-2019-1842

    Last Modified: 21 Nov 2024

    A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when certain sequences of actions are processed during an SSH login event on the affected device. An attacker could exploit this vulnerability by initiating an SSH session to the device with a specific sequence that presents the two usernames. A successful exploit could result in logging data misrepresentation, user enumeration, or, in certain circumstances, a command authorization bypass. See the Details section for more information.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-12555

    Last Modified: 21 Nov 2024

    In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-9642

    Last Modified: 21 Nov 2024

    An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created by the guest account, with execution via a proxy.php?hash=../../../../../var/lib/pydio/data/personal/guest/PoC.php request. This is related to plugins/action.share/src/Store/ShareStore.php.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-9647

    Last Modified: 21 Nov 2024

    Gila CMS 1.9.1 has XSS.

    Published: 5 Jun 2019
    4.6
    Medium

    CVE-2019-10637

    Last Modified: 21 Nov 2024

    Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices are vulnerable in manipulating a combination of IO pins to bypass the secure boot protection mechanism.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-9673

    Last Modified: 21 Nov 2024

    Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11984

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11980

    Last Modified: 21 Nov 2024

    A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11979

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11978

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11977

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11976

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11975

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11974

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11973

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11972

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11971

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11970

    Last Modified: 21 Nov 2024

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11969

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11968

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11967

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11985

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11986

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-12742

    Last Modified: 21 Nov 2024

    Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter).

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11966

    Last Modified: 21 Nov 2024

    A remote privilege escalation vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11965

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11964

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11963

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11962

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11961

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11960

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11959

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-9730

    Last Modified: 21 Nov 2024

    Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an unpublished API.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-11958

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.1
    High

    CVE-2019-11957

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019