CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-0171

    Last Modified: 21 Nov 2024

    Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 May 2019
    7.8
    High

    CVE-2019-11094

    Last Modified: 21 Nov 2024

    Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

    Published: 17 May 2019
    4.4
    Medium

    CVE-2019-11114

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.

    Published: 17 May 2019
    7.5
    High

    CVE-2019-0132

    Last Modified: 21 Nov 2024

    Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.

    Published: 17 May 2019
    9.8
    Critical

    CVE-2019-0172

    Last Modified: 21 Nov 2024

    A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.

    Published: 17 May 2019
    6.7
    Medium

    CVE-2019-11093

    Last Modified: 21 Nov 2024

    Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 May 2019
    4.4
    Medium

    CVE-2019-11095

    Last Modified: 21 Nov 2024

    Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.

    Published: 17 May 2019
    7.8
    High

    CVE-2019-0138

    Last Modified: 21 Nov 2024

    Improper directory permissions in Intel(R) ACU Wizard version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 17 May 2019
    9.1
    Critical

    CVE-2019-5883

    Last Modified: 21 Nov 2024

    An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 6.0 and later but before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. The issue comments feature could allow a user to comment on an issue which they shouldn't be allowed to.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5946

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.

    Published: 17 May 2019
    7.8
    High

    CVE-2019-5958

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 17 May 2019
    5.4
    Medium

    CVE-2019-5947

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Cabinet'.

    Published: 17 May 2019
    9.1
    Critical

    CVE-2019-5954

    Last Modified: 21 Nov 2024

    JR East Japan train operation information push notification App for Android version 1.2.4 and earlier allows remote attackers to bypass access restriction to obtain or alter the user's registered information via unspecified vectors.

    Published: 17 May 2019
    5.4
    Medium

    CVE-2019-5955

    Last Modified: 21 Nov 2024

    CREATE SD official App for Android version 1.0.2 and earlier allows remote attackers to bypass access restriction to lead a user to access an arbitrary website via vulnerable application and conduct phishing attacks.

    Published: 17 May 2019
    7.8
    High

    CVE-2019-5957

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5938

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the application 'Mail'.

    Published: 17 May 2019
    5.4
    Medium

    CVE-2019-5937

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or HTML via the user information.

    Published: 17 May 2019
    9.8
    Critical

    CVE-2019-5945

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5933

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.

    Published: 17 May 2019
    7.2
    High

    CVE-2019-5934

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5935

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.

    Published: 17 May 2019
    5.4
    Medium

    CVE-2019-5936

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to obtain files without access privileges via the application 'Work Flow'.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5939

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the application 'Portal'.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5940

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.10.1 allows remote attackers to inject arbitrary web script or HTML via the application 'Scheduler'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5941

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the Report without access privileges via the application 'Multi Report'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5942

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5943

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5944

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-5930

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5929

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via the application 'Memo'.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-5928

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to inject arbitrary web script or HTML via Customize Item function.

    Published: 17 May 2019
    8.7
    High

    CVE-2019-5931

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.

    Published: 17 May 2019
    4.8
    Medium

    CVE-2019-5932

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Portal'.

    Published: 17 May 2019
    9.8
    Critical

    CVE-2019-4279

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.

    Published: 17 May 2019
    5.3
    Medium

    CVE-2019-4119

    Last Modified: 21 Nov 2024

    IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster internal but also external target IP addresses. IBM X-Force ID: 158145.

    Published: 17 May 2019
    7.5
    High

    CVE-2018-20500

    Last Modified: 21 Nov 2024

    An insecure permissions issue was discovered in GitLab Community and Enterprise Edition 9.4 and later but before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. The runner registration token in the CI/CD settings could not be reset. This was a security risk if one of the maintainers leaves the group and they know the token.

    Published: 17 May 2019
    7.5
    High

    CVE-2018-19585

    Last Modified: 21 Nov 2024

    GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8937

    Last Modified: 21 Nov 2024

    HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8929

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8928

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8927

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource, selectDeviceDone, task, val10, and val11.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8926

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2019-8925

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via any file name, such as a schFilePath=C:\boot.ini value.

    Published: 17 May 2019
    6.1
    Medium

    CVE-2019-8924

    Last Modified: 21 Nov 2024

    XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.

    Published: 17 May 2019
    4.3
    Medium

    CVE-2018-20839

    Last Modified: 5 May 2025

    systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled.

    Published: 17 May 2019
    7.8
    High

    CVE-2019-10139

    Last Modified: 21 Nov 2024

    During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the admin and the appliance passwords as plain-text. At the of the deployment procedure, these files are deleted.

    Published: 17 May 2019
    5.4
    Medium

    CVE-2019-10909

    Last Modified: 21 Nov 2024

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

    Published: 16 May 2019
    9.8
    Critical

    CVE-2019-10910

    Last Modified: 21 Nov 2024

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

    Published: 16 May 2019
    7.5
    High

    CVE-2019-10911

    Last Modified: 21 Nov 2024

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

    Published: 16 May 2019
    7.1
    High

    CVE-2019-10912

    Last Modified: 21 Nov 2024

    In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.

    Published: 16 May 2019