CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-7127

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 23 May 2019
    8.8
    High

    CVE-2019-7111

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7118

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    7.5
    High

    CVE-2017-11559

    Last Modified: 21 Nov 2024

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7119

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7120

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    5.4
    Medium

    CVE-2017-11560

    Last Modified: 21 Nov 2024

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7124

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7117

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7128

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7088

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7112

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7113

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7098

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7102

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7099

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7100

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7101

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7103

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7104

    Last Modified: 21 Nov 2024

    Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7135

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7106

    Last Modified: 15 Sept 2026

    Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    7.5
    High

    CVE-2019-7097

    Last Modified: 21 Nov 2024

    Adobe Dreamweaver versions 19.0 and earlier have an insecure protocol implementation vulnerability. Successful exploitation could lead to sensitive data disclosure if smb request is subject to a relay attack.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7105

    Last Modified: 15 Sept 2026

    Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7107

    Last Modified: 21 Nov 2024

    Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-7130

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have a heap overflow vulnerability. Successful exploitation could lead to remote code execution.

    Published: 23 May 2019
    8.8
    High

    CVE-2019-7132

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an out-of-bounds write vulnerability. Successful exploitation could lead to remote code execution.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7133

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2017-11561

    Last Modified: 21 Nov 2024

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7134

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7138

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7136

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have an use after free vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    8.1
    High

    CVE-2017-11738

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.

    Published: 23 May 2019
    6.1
    Medium

    CVE-2017-11739

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.

    Published: 23 May 2019
    6.5
    Medium

    CVE-2019-7137

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.0.2 have a memory corruption vulnerability. Successful exploitation could lead to information disclosure.

    Published: 23 May 2019
    8.8
    High

    CVE-2017-11740

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.

    Published: 23 May 2019
    5.4
    Medium

    CVE-2017-13668

    Last Modified: 21 Nov 2024

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12301

    Last Modified: 21 Nov 2024

    The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root password to a blank value upon an upgrade. This was fixed in 5.6.44-85.0-2.

    Published: 23 May 2019
    4.3
    Medium

    CVE-2017-15029

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

    Published: 23 May 2019
    6.1
    Medium

    CVE-2017-15030

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 23 May 2019
    5.5
    Medium

    CVE-2017-15652

    Last Modified: 21 Nov 2024

    Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2017-17060

    Last Modified: 21 Nov 2024

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.

    Published: 23 May 2019
    5.4
    Medium

    CVE-2017-17061

    Last Modified: 21 Nov 2024

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 23 May 2019
    9.8
    Critical

    CVE-2017-5210

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.

    Published: 23 May 2019
    7.5
    High

    CVE-2017-5211

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2017-5212

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

    Published: 23 May 2019
    6.1
    Medium

    CVE-2017-5213

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12300

    Last Modified: 21 Nov 2024

    Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they can login as the victim.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12272

    Last Modified: 21 Nov 2024

    In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

    Published: 23 May 2019
    7.8
    High

    CVE-2019-4078

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to incorrect permissions set on MQ installation directories. IBM X-Force ID: 157190.

    Published: 23 May 2019