CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-6752

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.3.10826. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7620.

    Published: 3 Jun 2019
    5.5
    Medium

    CVE-2019-6756

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7769.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-6739

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way the product handles URIs within certain schemes. The product does not warn the user that a dangerous navigation is about to take place. Because special characters in the URI are not sanitized, this could lead to the execution of arbitrary commands. An attacker can leverage this vulnerability to execute code in the context of the current user at medium integrity. Was ZDI-CAN-7162.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-6738

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of TIScript. When processing the launch method the application does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability execute code in the context of the current process. Was ZDI-CAN-7250.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-6736

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of tiscript. When processing the System.Exec method the application does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7234.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-6737

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of TIScript. The issue lies in the handling of the openFile method, which allows for an arbitrary file write with attacker controlled data. An attacker can leverage this vulnerability execute code in the context of the current process. Was ZDI-CAN-7247.

    Published: 3 Jun 2019
    3.5
    Low

    CVE-2019-9753

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose information from invalid system entities. Following is the list of affected entities: Custom Pages, FAQ Articles, Service Catalogue Items, ITSM Configuration Items.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-9882

    Last Modified: 21 Nov 2024

    Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&[email protected]&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-9883

    Last Modified: 21 Nov 2024

    Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-11646

    Last Modified: 21 Nov 2024

    Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61. This vulnerability could allow Remote unauthorized command execution and unauthorized disclosure of information.

    Published: 3 Jun 2019
    7.5
    High

    CVE-2019-12593

    Last Modified: 21 Nov 2024

    IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.

    Published: 3 Jun 2019
    5.3
    Medium

    CVE-2019-3802

    Last Modified: 21 Nov 2024

    This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

    Published: 3 Jun 2019
    9.1
    Critical

    CVE-2019-3397

    Last Modified: 21 Nov 2024

    Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-11580

    Last Modified: 24 Oct 2025

    Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability.

    Published: 3 Jun 2019
    6.8
    Medium

    CVE-2019-12591

    Last Modified: 21 Nov 2024

    NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.

    Published: 3 Jun 2019
    —
    Unknown

    CVE-2019-12582

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12583. Reason: This candidate is a reservation duplicate of CVE-2019-12583. Notes: All CVE users should reference CVE-2019-12583 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Jun 2019
    8.8
    High

    CVE-2019-12589

    Last Modified: 21 Nov 2024

    In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-12585

    Last Modified: 21 Nov 2024

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

    Published: 3 Jun 2019
    6.1
    Medium

    CVE-2019-12584

    Last Modified: 21 Nov 2024

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.

    Published: 3 Jun 2019
    7.5
    High

    CVE-2018-16871

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.

    Published: 3 Jun 2019
    7.8
    High

    CVE-2019-12569

    Last Modified: 21 Nov 2024

    A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could cause the application to load libraries from the directory targeted by the URI link. The attacker could use this behavior to execute arbitrary commands on the system with the privileges of the targeted user, if the attacker can place a crafted library in a directory that is accessible to the vulnerable system.

    Published: 3 Jun 2019
    4.1
    Medium

    CVE-2019-12614

    Last Modified: 21 Nov 2024

    An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

    Published: 3 Jun 2019
    5
    Medium

    CVE-2019-10153

    Last Modified: 21 Nov 2024

    A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.

    Published: 3 Jun 2019
    9.8
    Critical

    CVE-2019-10160

    Last Modified: 21 Nov 2024

    A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.

    Published: 3 Jun 2019
    6.1
    Medium

    CVE-2019-12308

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.

    Published: 3 Jun 2019
    5.4
    Medium

    CVE-2019-12566

    Last Modified: 21 Nov 2024

    The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.

    Published: 2 Jun 2019
    9.8
    Critical

    CVE-2019-12564

    Last Modified: 21 Nov 2024

    In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames.

    Published: 2 Jun 2019
    8.8
    High

    CVE-2017-18376

    Last Modified: 21 Nov 2024

    An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.

    Published: 2 Jun 2019
    9.8
    Critical

    CVE-2019-12530

    Last Modified: 21 Nov 2024

    Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.

    Published: 2 Jun 2019
    7.5
    High

    CVE-2019-12615

    Last Modified: 21 Nov 2024

    An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).

    Published: 2 Jun 2019
    7.1
    High

    CVE-2019-12515

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure or a denial of service.

    Published: 1 Jun 2019
    6.5
    Medium

    CVE-2019-10175

    Last Modified: 21 Nov 2024

    A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the source namespace. This could allow users to clone any PVC in the cluster into their own namespace, effectively allowing access to other user's data.

    Published: 1 Jun 2019
    7.5
    High

    CVE-2019-12761

    Last Modified: 21 Nov 2024

    A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

    Published: 1 Jun 2019
    9.8
    Critical

    CVE-2019-10123

    Last Modified: 21 Nov 2024

    SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-10069

    Last Modified: 21 Nov 2024

    In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-9653

    Last Modified: 21 Nov 2024

    NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-6725

    Last Modified: 21 Nov 2024

    The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-9106

    Last Modified: 21 Nov 2024

    The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/convert.base64-encode/resource=index.php to read index.php.

    Published: 31 May 2019
    7.5
    High

    CVE-2019-9105

    Last Modified: 21 Nov 2024

    The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by retrieving password hashes via an inc/utils/REST_API.php?command=CallAPI&customurl=alladminusers call.

    Published: 31 May 2019
    7.3
    High

    CVE-2019-10049

    Last Modified: 21 Nov 2024

    It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an administrator user into opening a link shared through the application, that in turn opens a shared file that contains JavaScript code (that is executed in the context of the victim user to obtain sensitive information such as session identifiers and perform actions on behalf of him/her).

    Published: 31 May 2019
    7.2
    High

    CVE-2019-10048

    Last Modified: 21 Nov 2024

    The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user supplied input in the plugin's configuration options, allowing arbitrary shell commands to be entered that result in command execution on the underlying operating system, with the privileges of the local user running the web server. The attacker must be authenticated into the application with an administrator user account in order to be able to edit the affected plugin configuration.

    Published: 31 May 2019
    5.4
    Medium

    CVE-2019-10047

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the file upload and file preview features of the application. An authenticated attacker can upload an HTML file containing JavaScript code and afterwards a file preview URL can be used to access the uploaded file. If a malicious user shares an uploaded HTML file containing JavaScript code with another user of the application, and tricks an authenticated victim into accessing a URL that results in the HTML code being interpreted by the web browser, then the included JavaScript code is executed under the context of the victim user session.

    Published: 31 May 2019
    7.8
    High

    CVE-2019-5678

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may lead to code execution, denial of service or information disclosure.

    Published: 31 May 2019
    5.3
    Medium

    CVE-2019-10046

    Last Modified: 21 Nov 2024

    An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

    Published: 31 May 2019
    6.5
    Medium

    CVE-2019-10045

    Last Modified: 21 Nov 2024

    The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perform actions on behalf of him/her (if the session is still active).

    Published: 31 May 2019
    7.8
    High

    CVE-2019-10038

    Last Modified: 21 Nov 2024

    Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file.

    Published: 31 May 2019
    7.8
    High

    CVE-2019-10981

    Last Modified: 21 Nov 2024

    In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-9891

    Last Modified: 21 Nov 2024

    The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.

    Published: 31 May 2019
    8.8
    High

    CVE-2019-9875

    Last Modified: 7 Nov 2025

    Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-9874

    Last Modified: 7 Nov 2025

    Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

    Published: 31 May 2019