CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2018-13379

    Last Modified: 24 Oct 2025

    An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

    Published: 4 Jun 2019
    4.7
    Medium

    CVE-2018-13380

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below and Fortinet FortiProxy 2.0.0, 1.2.8 and below under SSL VPN web portal allows attacker to execute unauthorized malicious script code via the error or message handling parameters.

    Published: 4 Jun 2019
    4.2
    Medium

    CVE-2019-5307

    Last Modified: 21 Nov 2024

    Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS COUNT. As a result, an attacker can construct a rogue base station and replay the GUTI reallocation command message in certain conditions to tamper with GUTIs, or replay the Identity request message to obtain IMSIs. (Vulnerability ID: HWPSIRT-2019-04107)

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5284

    Last Modified: 21 Nov 2024

    There is a DoS vulnerability in RTSP module of Leland-AL00A Huawei smart phones versions earlier than Leland-AL00A 9.1.0.111(C00E111R2P10T8). Remote attackers could trick the user into opening a malformed RTSP media stream to exploit this vulnerability. Successful exploit could cause the affected phone abnormal, leading to a DoS condition. (Vulnerability ID: HWPSIRT-2019-02004)

    Published: 4 Jun 2019
    7.5
    High

    CVE-2019-5285

    Last Modified: 21 Nov 2024

    Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send crafted packets to the affected device to exploit this vulnerability. Due to insufficient verification of the packets, successful exploitation may cause the device reboot and denial of service (DoS) condition. (Vulnerability ID: HWPSIRT-2019-03109)

    Published: 4 Jun 2019
    6.8
    Medium

    CVE-2019-5215

    Last Modified: 21 Nov 2024

    There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1). When users establish connection and transfer data through Huawei Share, an attacker could sniff, spoof and do a series of operations to intrude the Huawei Share connection and launch a man-in-the-middle attack to obtain and tamper the data. (Vulnerability ID: HWPSIRT-2019-03109)

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-5283

    Last Modified: 21 Nov 2024

    There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than Emily-AL00A 9.0.0.167 (C00E81R1P21T8). When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and can perform some operations to access the setting page. As a result, the FRP function is bypassed.

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-5217

    Last Modified: 21 Nov 2024

    There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.150 (C00E61R1P8T8). An attacker could view the photos after a series of operations without unlocking the screen lock. Successful exploit could cause an information disclosure condition.

    Published: 4 Jun 2019
    6.7
    Medium

    CVE-2019-5300

    Last Modified: 21 Nov 2024

    There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.

    Published: 4 Jun 2019
    6.8
    Medium

    CVE-2019-5298

    Last Modified: 21 Nov 2024

    There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to the improper implementation of authentication for the serial port, an attacker could exploit this vulnerability by connecting to the affected products and running a series of commands.

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-5297

    Last Modified: 21 Nov 2024

    Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C185E2R1P12T8) have a Factory Reset Protection (FRP) bypass security vulnerability. Before the FRP account is verified and activated during the reset process, the attacker can perform some special operations to bypass the FRP function and obtain the right to use the mobile phone.

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-5306

    Last Modified: 21 Nov 2024

    There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily-AL00A 9.0.0.167(C00E81R1P21T8). When re-configuring the mobile phone using the FRP function, an attacker can delete the activation lock after a series of operations. As a result, the FRP function is bypassed and the attacker gains access to the smartphone.

    Published: 4 Jun 2019
    3.9
    Low

    CVE-2019-5296

    Last Modified: 21 Nov 2024

    Mate20 Huawei smartphones versions earlier than HMA-AL00C00B175 have an out-of-bounds read vulnerability. An attacker with a high permission runs some specific commands on the smartphone. Due to insufficient input verification, successful exploit may cause out-of-bounds read of the memory and the system abnormal.

    Published: 4 Jun 2019
    5.5
    Medium

    CVE-2019-5244

    Last Modified: 21 Nov 2024

    Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due to the lack of input validation. An attacker tricks the user who has root privilege to install an application on the smart phone, and the application can read some process information, which may cause sensitive information leak.

    Published: 4 Jun 2019
    4.6
    Medium

    CVE-2019-5281

    Last Modified: 21 Nov 2024

    There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2). When a local attacker uses the camera of a smartphone, the attacker can exploit this vulnerability to obtain sensitive information by performing a series of operations.

    Published: 4 Jun 2019
    9.8
    Critical

    CVE-2019-12730

    Last Modified: 21 Nov 2024

    aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.

    Published: 4 Jun 2019
    8.1
    High

    CVE-2019-12728

    Last Modified: 21 Nov 2024

    Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.

    Published: 4 Jun 2019
    7.5
    High

    CVE-2019-12727

    Last Modified: 21 Nov 2024

    On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead to an invalid memory read. To exploit the vulnerability, an attacker must craft an RTSP request with a large number of headers.

    Published: 4 Jun 2019
    9.8
    Critical

    CVE-2019-10149

    Last Modified: 6 Nov 2025

    A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5832

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5834

    Last Modified: 21 Nov 2024

    Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 4 Jun 2019
    4.3
    Medium

    CVE-2019-5838

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.

    Published: 4 Jun 2019
    5.9
    Medium

    CVE-2019-12814

    Last Modified: 27 Aug 2025

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.

    Published: 4 Jun 2019
    5.4
    Medium

    CVE-2019-10156

    Last Modified: 21 Nov 2024

    A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.

    Published: 4 Jun 2019
    8.8
    High

    CVE-2019-5831

    Last Modified: 21 Nov 2024

    Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5837

    Last Modified: 21 Nov 2024

    Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Jun 2019
    4.3
    Medium

    CVE-2019-5839

    Last Modified: 21 Nov 2024

    Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.

    Published: 4 Jun 2019
    8.8
    High

    CVE-2019-5828

    Last Modified: 21 Nov 2024

    Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 4 Jun 2019
    8.8
    High

    CVE-2019-5829

    Last Modified: 21 Nov 2024

    Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5830

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Jun 2019
    4.3
    Medium

    CVE-2019-5833

    Last Modified: 21 Nov 2024

    Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-5835

    Last Modified: 21 Nov 2024

    Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 4 Jun 2019
    8.8
    High

    CVE-2019-5836

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Jun 2019
    4.3
    Medium

    CVE-2019-5840

    Last Modified: 21 Nov 2024

    Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 4 Jun 2019
    6.5
    Medium

    CVE-2019-10009

    Last Modified: 21 Nov 2024

    A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory.

    Published: 3 Jun 2019
    6.1
    Medium

    CVE-2019-9838

    Last Modified: 21 Nov 2024

    VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.

    Published: 3 Jun 2019
    6.1
    Medium

    CVE-2019-9839

    Last Modified: 21 Nov 2024

    VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-12548

    Last Modified: 21 Nov 2024

    Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-10883

    Last Modified: 21 Nov 2024

    Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-11185

    Last Modified: 21 Nov 2024

    The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and prepending "magic bytes" to the payload to pass MIME checks. Specifically, an unauthenticated remote user submits a crafted file upload POST request to the REST api remote_upload endpoint. The file contains data that will fool the plugin's MIME check into classifying it as an image (which is a whitelisted file extension) and finally a trailing .phtml file extension.

    Published: 3 Jun 2019
    7.8
    High

    CVE-2019-12097

    Last Modified: 21 Nov 2024

    Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-11367

    Last Modified: 21 Nov 2024

    An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

    Published: 3 Jun 2019
    5.4
    Medium

    CVE-2019-11368

    Last Modified: 21 Nov 2024

    Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-12169

    Last Modified: 21 Nov 2024

    ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive to the mods/_core/languages/language_import.php (aka Import New Language) or mods/_standard/patcher/index_admin.php (aka Patcher) component.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-11369

    Last Modified: 21 Nov 2024

    An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-11356

    Last Modified: 21 Nov 2024

    The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

    Published: 3 Jun 2019
    5.4
    Medium

    CVE-2019-11370

    Last Modified: 21 Nov 2024

    Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

    Published: 3 Jun 2019
    4.7
    Medium

    CVE-2019-6588

    Last Modified: 21 Nov 2024

    In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-11509

    Last Modified: 21 Nov 2024

    In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can exploit Incorrect Access Control to execute arbitrary code on the appliance.

    Published: 3 Jun 2019
    9
    Critical

    CVE-2019-12373

    Last Modified: 21 Nov 2024

    Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.

    Published: 3 Jun 2019