CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-7826

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

    Published: 22 May 2019
    8.8
    High

    CVE-2018-7825

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2018-7816

    Last Modified: 21 Nov 2024

    A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to delete an arbitrary file.

    Published: 22 May 2019
    4.9
    Medium

    CVE-2018-7824

    Last Modified: 21 Nov 2024

    An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2017-5984

    Last Modified: 21 Nov 2024

    In libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.

    Published: 22 May 2019
    7.8
    High

    CVE-2018-7840

    Last Modified: 21 Nov 2024

    A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorrect DLL.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2018-7841

    Last Modified: 3 Nov 2025

    A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

    Published: 22 May 2019
    8.8
    High

    CVE-2017-6912

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

    Published: 22 May 2019
    8.8
    High

    CVE-2017-8340

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

    Published: 22 May 2019
    5.3
    Medium

    CVE-2017-8341

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

    Published: 22 May 2019
    7.2
    High

    CVE-2017-8777

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2017-9808

    Last Modified: 21 Nov 2024

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 22 May 2019
    5.3
    Medium

    CVE-2017-9809

    Last Modified: 21 Nov 2024

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2019-7844

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 13.0.2 has an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7842

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 13.0.2 has a use-after-free vulnerability. Successful exploitation could lead to remote code execution.

    Published: 22 May 2019
    7.8
    High

    CVE-2019-5627

    Last Modified: 21 Nov 2024

    The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encoded strings, i.e. clear text. These persist in the cache even if the user logs out. This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the iOS device or compromise it with a malicious app.

    Published: 22 May 2019
    7.8
    High

    CVE-2019-5626

    Last Modified: 21 Nov 2024

    The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This file persists until the user logs out or the session times out from non-usage (30 days of no user activity). This can allow an attacker to compromise the affected BlueCats network implementation. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.

    Published: 22 May 2019
    7.1
    High

    CVE-2019-5625

    Last Modified: 21 Nov 2024

    The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-7841

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-7836

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-7835

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-7834

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-7833

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-7832

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 22 May 2019
    8.8
    High

    CVE-2018-14729

    Last Modified: 21 Nov 2024

    The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-11536

    Last Modified: 21 Nov 2024

    Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7831

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2019-12167

    Last Modified: 21 Nov 2024

    httpGetSet/httpGet.htm on Emerson Network Power Liebert Challenger 5.1E0.5 devices allows XSS via the statusstr parameter.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7830

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7829

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-8442

    Last Modified: 21 Nov 2024

    The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7828

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2019-3402

    Last Modified: 21 Nov 2024

    The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7827

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    8.1
    High

    CVE-2019-8443

    Last Modified: 21 Nov 2024

    The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7825

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    5.3
    Medium

    CVE-2019-3403

    Last Modified: 21 Nov 2024

    The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7826

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7824

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2018-7202

    Last Modified: 21 Nov 2024

    An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2019-7823

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7822

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    5.3
    Medium

    CVE-2019-3401

    Last Modified: 21 Nov 2024

    The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2019-7821

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7818

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019
    5.3
    Medium

    CVE-2017-6514

    Last Modified: 21 Nov 2024

    WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-11231

    Last Modified: 21 Nov 2024

    An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official documentation for installation step 10, an admin is required to upload all the files, including the .htaccess files, and run a health check. However, what is overlooked is that the Apache HTTP Server by default no longer enables the AllowOverride directive, leading to data/users/admin.xml password exposure. The passwords are hashed but this can be bypassed by starting with the data/other/authorization.xml API key. This allows one to target the session state, since they decided to roll their own implementation. The cookie_name is crafted information that can be leaked from the frontend (site name and version). If a someone leaks the API key and the admin username, then they can bypass authentication. To do so, they need to supply a cookie based on an SHA-1 computation of this known information. The vulnerability exists in the admin/theme-edit.php file. This file checks for forms submissions via POST requests, and for the csrf nonce. If the nonce sent is correct, then the file provided by the user is uploaded. There is a path traversal allowing write access outside the jailed themes directory root. Exploiting the traversal is not necessary because the .htaccess file is ignored. A contributing factor is that there isn't another check on the extension before saving the file, with the assumption that the parameter content is safe. This allows the creation of web accessible and executable files with arbitrary content.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-11634

    Last Modified: 6 Nov 2025

    Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-11880

    Last Modified: 21 Nov 2024

    CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.

    Published: 22 May 2019
    8.8
    High

    CVE-2019-7820

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 22 May 2019