CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-12243

    Last Modified: 21 Nov 2024

    Istio 1.1.x through 1.1.6 has Incorrect Access Control.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-12538

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5359

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-5358

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5357

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-5356

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2019-5355

    Last Modified: 21 Nov 2024

    A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5354

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5353

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-5352

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-12541

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-12542

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5351

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5350

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5349

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5348

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-5347

    Last Modified: 21 Nov 2024

    A remote authentication bypass vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-12543

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5346

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5345

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5344

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5343

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5342

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5341

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5340

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5339

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    8.8
    High

    CVE-2019-5338

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    6.3
    Medium

    CVE-2018-7125

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2018-7124

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    7.5
    High

    CVE-2018-7123

    Last Modified: 21 Nov 2024

    A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    5.3
    Medium

    CVE-2018-7122

    Last Modified: 21 Nov 2024

    A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2018-7121

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    5.3
    Medium

    CVE-2019-5392

    Last Modified: 21 Nov 2024

    A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    4.3
    Medium

    CVE-2019-5393

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Published: 5 Jun 2019
    9
    Critical

    CVE-2019-12739

    Last Modified: 21 Nov 2024

    lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).

    Published: 5 Jun 2019
    8.2
    High

    CVE-2017-6261

    Last Modified: 21 Nov 2024

    NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection mechanisms are insufficient, may lead to denial of service or information disclosure.

    Published: 5 Jun 2019
    6.5
    Medium

    CVE-2019-12616

    Last Modified: 21 Nov 2024

    An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance through a broken <img> tag pointing at the victim's phpMyAdmin database, and the attacker can potentially deliver a payload (such as a specific INSERT or DELETE statement) to the victim.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-11768

    Last Modified: 21 Nov 2024

    An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

    Published: 5 Jun 2019
    9.8
    Critical

    CVE-2019-12928

    Last Modified: 21 Nov 2024

    The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue

    Published: 5 Jun 2019
    7.8
    High

    CVE-2019-12795

    Last Modified: 21 Nov 2024

    daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorization rule. A local attacker could connect to this server socket and issue D-Bus method calls. (Note that the server socket only accepts a single connection, so the attacker would have to discover the server and connect to the socket before its owner does.)

    Published: 5 Jun 2019
    8.6
    High

    CVE-2019-12735

    Last Modified: 11 Nov 2025

    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

    Published: 5 Jun 2019
    6.1
    Medium

    CVE-2019-5588

    Last Modified: 21 Nov 2024

    A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "err" parameter of the error process HTTP requests.

    Published: 4 Jun 2019
    6.1
    Medium

    CVE-2019-5586

    Last Modified: 21 Nov 2024

    A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.2.0 to 5.6.10, 6.0.0 to 6.0.4 under SSL VPN web portal may allow an attacker to execute unauthorized malicious script code via the "param" parameter of the error process HTTP requests.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5587

    Last Modified: 21 Nov 2024

    Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-10636

    Last Modified: 21 Nov 2024

    Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices allow reprogramming flash memory to bypass the secure boot protection mechanism.

    Published: 4 Jun 2019
    6.1
    Medium

    CVE-2018-13384

    Last Modified: 21 Nov 2024

    A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

    Published: 4 Jun 2019
    9.1
    Critical

    CVE-2018-13382

    Last Modified: 24 Oct 2025

    An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

    Published: 4 Jun 2019
    8.1
    High

    CVE-2019-12210

    Last Modified: 21 Nov 2024

    In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.

    Published: 4 Jun 2019
    7.5
    High

    CVE-2019-12209

    Last Modified: 21 Nov 2024

    Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is enabled in the PAM configuration, part of the file contents of a symlink target will be logged, possibly revealing sensitive information.

    Published: 4 Jun 2019
    5.3
    Medium

    CVE-2018-13381

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

    Published: 4 Jun 2019