CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-15530

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.

    Published: 13 May 2019
    6.1
    Medium

    CVE-2018-12304

    Last Modified: 21 Nov 2024

    Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.

    Published: 13 May 2019
    5.4
    Medium

    CVE-2018-12303

    Last Modified: 21 Nov 2024

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

    Published: 13 May 2019
    6.1
    Medium

    CVE-2018-12302

    Last Modified: 21 Nov 2024

    Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

    Published: 13 May 2019
    7.5
    High

    CVE-2018-12301

    Last Modified: 21 Nov 2024

    Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.

    Published: 13 May 2019
    6.1
    Medium

    CVE-2018-12300

    Last Modified: 21 Nov 2024

    Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

    Published: 13 May 2019
    5.4
    Medium

    CVE-2018-12299

    Last Modified: 21 Nov 2024

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

    Published: 13 May 2019
    7.5
    High

    CVE-2018-12298

    Last Modified: 21 Nov 2024

    Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

    Published: 13 May 2019
    6.1
    Medium

    CVE-2018-12297

    Last Modified: 21 Nov 2024

    Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

    Published: 13 May 2019
    7.5
    High

    CVE-2018-12296

    Last Modified: 21 Nov 2024

    Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

    Published: 13 May 2019
    9.8
    Critical

    CVE-2018-12295

    Last Modified: 21 Nov 2024

    SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

    Published: 13 May 2019
    9.8
    Critical

    CVE-2018-14714

    Last Modified: 21 Nov 2024

    System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.

    Published: 13 May 2019
    8.1
    High

    CVE-2018-14713

    Last Modified: 21 Nov 2024

    Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL parameter.

    Published: 13 May 2019
    6.5
    Medium

    CVE-2018-14712

    Last Modified: 21 Nov 2024

    Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.

    Published: 13 May 2019
    6.5
    Medium

    CVE-2018-14711

    Last Modified: 21 Nov 2024

    Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.

    Published: 13 May 2019
    6.1
    Medium

    CVE-2018-14710

    Last Modified: 21 Nov 2024

    Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.

    Published: 13 May 2019
    7.5
    High

    CVE-2018-19037

    Last Modified: 21 Nov 2024

    On Virgin Media wireless router 3.0 hub devices, the web interface is vulnerable to denial of service. When POST requests are sent and keep the connection open, the router lags and becomes unusable to anyone currently using the web interface.

    Published: 13 May 2019
    7.5
    High

    CVE-2019-12041

    Last Modified: 21 Nov 2024

    lib/common/html_re.js in remarkable 1.7.1 allows Regular Expression Denial of Service (ReDoS) via a CDATA section.

    Published: 13 May 2019
    9.8
    Critical

    CVE-2019-11888

    Last Modified: 21 Nov 2024

    Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, which allows attackers to obtain sensitive information or gain privileges.

    Published: 13 May 2019
    5.4
    Medium

    CVE-2018-20838

    Last Modified: 21 Nov 2024

    ampforwp_save_steps_data in the AMP for WP plugin before 0.9.97.21 for WordPress allows stored XSS.

    Published: 13 May 2019
    8.8
    High

    CVE-2019-11886

    Last Modified: 21 Nov 2024

    The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

    Published: 13 May 2019
    6.8
    Medium

    CVE-2019-11885

    Last Modified: 21 Nov 2024

    eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command.

    Published: 12 May 2019
    5.5
    Medium

    CVE-2019-10743

    Last Modified: 21 Nov 2024

    All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.

    Published: 12 May 2019
    7.5
    High

    CVE-2019-12312

    Last Modified: 21 Nov 2024

    In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IKEv2 IKE_SA_INIT exchange, followed by a bogus INFORMATIONAL exchange instead of the normallly expected IKE_AUTH exchange. This affects send_v2N_spi_response_from_state() in programs/pluto/ikev2_send.c that will then trigger a NULL pointer dereference leading to a restart of libreswan.

    Published: 12 May 2019
    5.5
    Medium

    CVE-2019-11833

    Last Modified: 21 Nov 2024

    fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.

    Published: 11 May 2019
    5.3
    Medium

    CVE-2019-5437

    Last Modified: 21 Nov 2024

    Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

    Published: 10 May 2019
    5.3
    Medium

    CVE-2019-5438

    Last Modified: 21 Nov 2024

    Path traversal using symlink in npm harp module versions <= 0.29.0.

    Published: 10 May 2019
    5.9
    Medium

    CVE-2019-3566

    Last Modified: 21 Nov 2024

    A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover previously sent messages. This behavior requires independent knowledge of metadata for previous messages, which are not available publicly. This issue affects WhatsApp for Android 2.19.52 and 2.19.54 - 2.19.103, as well as WhatsApp Business for Android starting in v2.19.22 until v2.19.38.

    Published: 10 May 2019
    5.5
    Medium

    CVE-2019-5677

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DeviceIoControl where the software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to denial of service.

    Published: 10 May 2019
    6.7
    Medium

    CVE-2019-5676

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

    Published: 10 May 2019
    7.8
    High

    CVE-2019-5675

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes, which may lead to denial of service, escalation of privileges, or information disclosure.

    Published: 10 May 2019
    —
    Unknown

    CVE-2018-8812

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-15610. Reason: This candidate is a reservation duplicate of CVE-2018-15610. Notes: All CVE users should reference CVE-2018-15610 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 May 2019
    6.5
    Medium

    CVE-2019-11000

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2019-11059

    Last Modified: 21 Nov 2024

    Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

    Published: 10 May 2019
    7.5
    High

    CVE-2019-5496

    Last Modified: 21 Nov 2024

    Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2019-11066

    Last Modified: 21 Nov 2024

    openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method.

    Published: 10 May 2019
    7.5
    High

    CVE-2019-5495

    Last Modified: 21 Nov 2024

    OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

    Published: 10 May 2019
    7.5
    High

    CVE-2019-5494

    Last Modified: 21 Nov 2024

    OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2018-7120

    Last Modified: 21 Nov 2024

    A security vulnerability in the HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy running firmware 5.00.50, which is part of the HPE Synergy Custom SPP 2018.11.20190205, could allow local or remote unauthorized elevation of privilege.

    Published: 10 May 2019
    7
    High

    CVE-2018-7119

    Last Modified: 21 Nov 2024

    A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series. STDSEC-STANDARD SECURITY PROD All prior versions before T6533L01^ADU or T6533H05^ADW, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND and all versions on H-series . Note that some commands in NonStop Safeguard and NonStop Standard Security software require username and password to be passed as command line parameters, which may lead to a local disclosure of the credentials.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2018-7084

    Last Modified: 21 Nov 2024

    A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system. An attacker could use this ability to copy files, read configuration, write files, delete files, or reboot the device. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.1

    Published: 10 May 2019
    6.1
    Medium

    CVE-2018-7064

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

    Published: 10 May 2019
    7.2
    High

    CVE-2018-7082

    Last Modified: 21 Nov 2024

    A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. Workaround: None. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

    Published: 10 May 2019
    7.5
    High

    CVE-2018-7083

    Last Modified: 21 Nov 2024

    If a process running within Aruba Instant crashes, it may leave behind a "core dump", which contains the memory contents of the process at the time it crashed. It was discovered that core dumps are stored in a way that unauthenticated users can access them through the Aruba Instant web interface. Core dumps could contain sensitive information such as keys and passwords. Workaround: Block access to the Aruba Instant web interface from all untrusted users. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

    Published: 10 May 2019
    5.5
    Medium

    CVE-2019-11879

    Last Modified: 21 Nov 2024

    The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.

    Published: 10 May 2019
    7.5
    High

    CVE-2019-11082

    Last Modified: 21 Nov 2024

    core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Traversal, resulting in the overwrite of local files with the contents of an archive.

    Published: 10 May 2019
    7.5
    High

    CVE-2017-12884

    Last Modified: 21 Nov 2024

    OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.

    Published: 10 May 2019
    6.1
    Medium

    CVE-2017-12885

    Last Modified: 21 Nov 2024

    OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 10 May 2019
    5.4
    Medium

    CVE-2019-4204

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159125.

    Published: 10 May 2019
    5.3
    Medium

    CVE-2018-1990

    Last Modified: 21 Nov 2024

    IBM Cloud App Management V2018.2.0, V2018.4.0, and V2018.4.1 could allow an attacker to obtain sensitive configuration information using a specially crafted HTTP request. IBM X-Force ID: 154283.

    Published: 10 May 2019