CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-9871

    Last Modified: 21 Nov 2024

    Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.

    Published: 31 May 2019
    4.3
    Medium

    CVE-2019-10323

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 31 May 2019
    4.3
    Medium

    CVE-2019-10326

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset warning counts for future builds.

    Published: 31 May 2019
    4.3
    Medium

    CVE-2019-10321

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 31 May 2019
    4.3
    Medium

    CVE-2019-10322

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 31 May 2019
    5.4
    Medium

    CVE-2019-10325

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.

    Published: 31 May 2019
    8.1
    High

    CVE-2019-10327

    Last Modified: 21 Nov 2024

    An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses external entities for extraction of secrets from the Jenkins master, server-side request forgery, or denial-of-service attacks.

    Published: 31 May 2019
    8.8
    High

    CVE-2019-10329

    Last Modified: 21 Nov 2024

    Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 31 May 2019
    7.5
    High

    CVE-2019-10330

    Last Modified: 21 Nov 2024

    Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.

    Published: 31 May 2019
    6.5
    Medium

    CVE-2019-10324

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, GradleReleaseApiAction#doStaging, MavenReleaseApiAction#doStaging, and UnifiedPromoteBuildAction#doSubmit allowed attackers to schedule a release build, perform release staging for Gradle and Maven projects, and promote previously staged builds, respectively.

    Published: 31 May 2019
    6.1
    Medium

    CVE-2019-12507

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path parameter.

    Published: 31 May 2019
    8.8
    High

    CVE-2019-12502

    Last Modified: 21 Nov 2024

    There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account via the /admin/access URI.

    Published: 31 May 2019
    6.5
    Medium

    CVE-2019-12500

    Last Modified: 21 Nov 2024

    The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentication check. Other affected commands include suddenly braking, locking, and unlocking.

    Published: 31 May 2019
    8.1
    High

    CVE-2019-12499

    Last Modified: 21 Nov 2024

    Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also needs to be terminated as root from the host (either by stopping it ungracefully (e.g., SIGKILL), or by using the --shutdown control command). This is similar to CVE-2019-5736.

    Published: 31 May 2019
    7.5
    High

    CVE-2019-12496

    Last Modified: 21 Nov 2024

    An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificates by default.

    Published: 31 May 2019
    5.5
    Medium

    CVE-2019-12495

    Last Modified: 21 Nov 2024

    An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-byte out-of-bounds write in the gsym_addr function in x86_64-gen.c. This occurs because tccasm.c mishandles section switches.

    Published: 31 May 2019
    7.1
    High

    CVE-2019-12493

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.

    Published: 31 May 2019
    9.8
    Critical

    CVE-2019-10126

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.

    Published: 31 May 2019
    9.9
    Critical

    CVE-2019-10328

    Last Modified: 21 Nov 2024

    Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary methods, bypassing typical sandbox protection.

    Published: 31 May 2019
    7.8
    High

    CVE-2019-12483

    Last Modified: 14 Mar 2025

    An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

    Published: 30 May 2019
    7.5
    High

    CVE-2019-12482

    Last Modified: 14 Mar 2025

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

    Published: 30 May 2019
    5.5
    Medium

    CVE-2019-12481

    Last Modified: 14 Mar 2025

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

    Published: 30 May 2019
    7.5
    High

    CVE-2019-12480

    Last Modified: 21 Nov 2024

    BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2015-2230

    Last Modified: 21 Nov 2024

    Synacor Zimbra Collaboration Server 8.x before 8.7.0 has Reflected XSS in admin console.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2015-7609

    Last Modified: 21 Nov 2024

    Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.

    Published: 30 May 2019
    7.1
    High

    CVE-2019-9723

    Last Modified: 21 Nov 2024

    LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the class PluginRegistry.

    Published: 30 May 2019
    4.8
    Medium

    CVE-2018-10948

    Last Modified: 21 Nov 2024

    Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2018-14425

    Last Modified: 21 Nov 2024

    There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.

    Published: 30 May 2019
    7.8
    High

    CVE-2018-9193

    Last Modified: 24 Mar 2025

    A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into an exploit chain, which allows a user to gain system privileges on Microsoft Windows.

    Published: 30 May 2019
    7.8
    High

    CVE-2018-13368

    Last Modified: 21 Nov 2024

    A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attacker to execute unauthorized code or commands via the command injection.

    Published: 30 May 2019
    7.8
    High

    CVE-2018-9191

    Last Modified: 21 Nov 2024

    A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.

    Published: 30 May 2019
    7.8
    High

    CVE-2018-4048

    Last Modified: 21 Nov 2024

    An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of the Desktop Galaxy Updater to exploit this vulnerability and execute arbitrary code with SYSTEM privileges.

    Published: 30 May 2019
    8.6
    High

    CVE-2018-20840

    Last Modified: 21 Nov 2024

    An unhandled exception vulnerability exists during Google Sign-In with Google API C++ Client before 2019-04-10. It potentially causes an outage of third-party services that were not designed to recover from exceptions. On the client, ID token handling can cause an unhandled exception because of misinterpretation of an integer as a string, resulting in denial-of-service and then other users can no longer login/sign-in to the affected third-party service. Once this third-party service uses Google Sign-In with google-api-cpp-client, a malicious user can trigger this client/auth/oauth2_authorization.cc vulnerability by requesting the client to receive the ID token from a Google authentication server.

    Published: 30 May 2019
    5.3
    Medium

    CVE-2018-15131

    Last Modified: 21 Nov 2024

    An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.

    Published: 30 May 2019
    8.8
    High

    CVE-2019-3846

    Last Modified: 21 Nov 2024

    A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2019-12461

    Last Modified: 21 Nov 2024

    Web Port 1.19.1 allows XSS via the /log type parameter.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2019-12460

    Last Modified: 21 Nov 2024

    Web Port 1.19.1 allows XSS via the /access/setup type parameter.

    Published: 30 May 2019
    5.3
    Medium

    CVE-2019-12459

    Last Modified: 21 Nov 2024

    FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01.

    Published: 30 May 2019
    5.3
    Medium

    CVE-2019-12458

    Last Modified: 21 Nov 2024

    FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01.

    Published: 30 May 2019
    5.3
    Medium

    CVE-2019-12457

    Last Modified: 21 Nov 2024

    FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01.

    Published: 30 May 2019
    5.4
    Medium

    CVE-2019-11269

    Last Modified: 21 Nov 2024

    Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

    Published: 30 May 2019
    7.5
    High

    CVE-2019-6469

    Last Modified: 21 Nov 2024

    An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Versions affected: BIND 9.10.5-S1 -> 9.11.6-S1 of BIND 9 Supported Preview Edition.

    Published: 30 May 2019
    8.8
    High

    CVE-2018-8029

    Last Modified: 21 Nov 2024

    In Apache Hadoop versions 3.0.0-alpha1 to 3.1.0, 2.9.0 to 2.9.1, and 2.2.0 to 2.8.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

    Published: 30 May 2019
    6.1
    Medium

    CVE-2018-18631

    Last Modified: 21 Nov 2024

    mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.

    Published: 29 May 2019
    6.1
    Medium

    CVE-2018-14013

    Last Modified: 21 Nov 2024

    Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.

    Published: 29 May 2019
    6.5
    Medium

    CVE-2019-6981

    Last Modified: 21 Nov 2024

    Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component.

    Published: 29 May 2019
    9.8
    Critical

    CVE-2018-20160

    Last Modified: 21 Nov 2024

    ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd.

    Published: 29 May 2019
    9.8
    Critical

    CVE-2019-6980

    Last Modified: 21 Nov 2024

    Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component.

    Published: 29 May 2019
    9.8
    Critical

    CVE-2019-9670

    Last Modified: 4 Nov 2025

    mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

    Published: 29 May 2019
    5.3
    Medium

    CVE-2018-13365

    Last Modified: 21 Nov 2024

    An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page.

    Published: 29 May 2019