CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2018-1790

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 148944.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2017-12795

    Last Modified: 21 Nov 2024

    OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

    Published: 10 May 2019
    6.5
    Medium

    CVE-2019-11878

    Last Modified: 21 Nov 2024

    An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as the camera can craft a message with a size field larger than 0x80000000 and send it to the camera, related to an integer overflow or use of a negative number. This then crashes the camera for about 120 seconds.

    Published: 10 May 2019
    8.8
    High

    CVE-2017-12789

    Last Modified: 21 Nov 2024

    Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

    Published: 10 May 2019
    9.8
    Critical

    CVE-2015-1006

    Last Modified: 21 Nov 2024

    A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

    Published: 10 May 2019
    10
    Critical

    CVE-2019-1867

    Last Modified: 21 Nov 2024

    A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.

    Published: 10 May 2019
    5.4
    Medium

    CVE-2019-11871

    Last Modified: 21 Nov 2024

    The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.

    Published: 10 May 2019
    7.5
    High

    CVE-2019-18408

    Last Modified: 21 Nov 2024

    archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

    Published: 10 May 2019
    3.3
    Low

    CVE-2019-11884

    Last Modified: 21 Nov 2024

    The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.

    Published: 10 May 2019
    4.8
    Medium

    CVE-2018-20837

    Last Modified: 21 Nov 2024

    include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.

    Published: 9 May 2019
    6.1
    Medium

    CVE-2019-11870

    Last Modified: 21 Nov 2024

    Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the templates/2k11/admin/media_items.tpl Media Library feature.

    Published: 9 May 2019
    6.1
    Medium

    CVE-2019-11869

    Last Modified: 21 Nov 2024

    The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes from an admin user (it actually only verifies that the request is for an admin page). An unauthenticated attacker can inject a payload into the plugin settings, such as the yuzo_related_post_css_and_style setting.

    Published: 9 May 2019
    7.7
    High

    CVE-2019-7652

    Last Modified: 21 Nov 2024

    TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main dashboard. Thus, it is possible to do port scans on localhost and intranet hosts.

    Published: 9 May 2019
    7.5
    High

    CVE-2016-1600

    Last Modified: 21 Nov 2024

    The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.

    Published: 9 May 2019
    —
    Unknown

    CVE-2019-11563

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 May 2019
    6.1
    Medium

    CVE-2019-1568

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2017-12757

    Last Modified: 21 Nov 2024

    Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i and Tech Job Script 9.27i and Tech Movie Script 7.51i and Tech Multi Vendor Script 6.63i and Tech Social Networking Script 3.08i and Tech Travel Script 9.49. The impact is: Code execution (remote).

    Published: 9 May 2019
    9.8
    Critical

    CVE-2017-12758

    Last Modified: 21 Nov 2024

    https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2017-12759

    Last Modified: 21 Nov 2024

    Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).

    Published: 9 May 2019
    8.8
    High

    CVE-2017-12760

    Last Modified: 21 Nov 2024

    Ynet Interactive - http://demo.ynetinteractive.com/mobiketa/ Mobiketa 4.0 is affected by: SQL Injection. The impact is: Code execution (remote).

    Published: 9 May 2019
    7.5
    High

    CVE-2017-12761

    Last Modified: 21 Nov 2024

    http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.

    Published: 9 May 2019
    7.5
    High

    CVE-2019-11842

    Last Modified: 21 Nov 2024

    An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

    Published: 9 May 2019
    7.1
    High

    CVE-2017-12778

    Last Modified: 21 Nov 2024

    The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file at the C:\Users\<username>\Roaming\qBittorrent pathname. The attacker must change the value of the "locked" attribute to "false" within the "Locking" stanza. NOTE: This is an intended behavior. See https://github.com/qbittorrent/qBittorrent/wiki/I-forgot-my-UI-lock-password

    Published: 9 May 2019
    6.5
    Medium

    CVE-2017-12790

    Last Modified: 21 Nov 2024

    Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.

    Published: 9 May 2019
    6.5
    Medium

    CVE-2017-12804

    Last Modified: 21 Nov 2024

    The iwgif_init_screen function in imagew-gif.c:510 in ImageWorsener 1.3.2 allows remote attackers to cause a denial of service (hmemory exhaustion) via a crafted file.

    Published: 9 May 2019
    6.3
    Medium

    CVE-2019-4072

    Last Modified: 21 Nov 2024

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to remain idle within the application even when a user has logged out. Utilizing the application back button users can remain logged in as the current user for a short period of time, therefore users are presented with information for Spectrum Control Application. IBM X-Force ID: 157064.

    Published: 9 May 2019
    8.8
    High

    CVE-2019-4071

    Last Modified: 21 Nov 2024

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.

    Published: 9 May 2019
    7.5
    High

    CVE-2019-7181

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.

    Published: 9 May 2019
    6.1
    Medium

    CVE-2017-12788

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.

    Published: 9 May 2019
    7.8
    High

    CVE-2019-6566

    Last Modified: 21 Nov 2024

    GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system.

    Published: 9 May 2019
    5.6
    Medium

    CVE-2019-6544

    Last Modified: 21 Nov 2024

    GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-6548

    Last Modified: 21 Nov 2024

    GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

    Published: 9 May 2019
    7.8
    High

    CVE-2019-6546

    Last Modified: 21 Nov 2024

    GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.

    Published: 9 May 2019
    7.8
    High

    CVE-2019-6564

    Last Modified: 21 Nov 2024

    GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

    Published: 9 May 2019
    7.8
    High

    CVE-2019-9847

    Last Modified: 21 Nov 2024

    A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an executable on the target users file system. If the hyperlink is activated by the victim the executable target is unconditionally launched. Under Windows and macOS when processing a hyperlink target explicitly activated by the user there was no judgment made on whether the target was an executable file, so such executable targets were launched unconditionally. This issue affects: All LibreOffice Windows and macOS versions prior to 6.1.6; LibreOffice Windows and macOS versions in the 6.2 series prior to 6.2.3.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11353

    Last Modified: 21 Nov 2024

    The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed in a later firmware version.

    Published: 9 May 2019
    4.9
    Medium

    CVE-2019-0226

    Last Modified: 21 Nov 2024

    Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf version before 4.2.5 is impacted. User should upgrade to Apache Karaf 4.2.5 or later.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11839

    Last Modified: 21 Nov 2024

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11838

    Last Modified: 21 Nov 2024

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.

    Published: 9 May 2019
    7.5
    High

    CVE-2019-11837

    Last Modified: 21 Nov 2024

    njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related to nxt_utf8_next in nxt/nxt_utf8.h and njs_string_offset in njs/njs_string.c.

    Published: 9 May 2019
    4.6
    Medium

    CVE-2019-11836

    Last Modified: 21 Nov 2024

    The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persisting after a logout.

    Published: 9 May 2019
    5.5
    Medium

    CVE-2019-11820

    Last Modified: 21 Nov 2024

    Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11835

    Last Modified: 22 Jul 2025

    cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11834

    Last Modified: 22 Jul 2025

    cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

    Published: 9 May 2019
    7.5
    High

    CVE-2019-11832

    Last Modified: 21 Nov 2024

    TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the applications used for image processing, as demonstrated by ImageMagick or GraphicsMagick.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11831

    Last Modified: 21 Nov 2024

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-11830

    Last Modified: 21 Nov 2024

    PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.

    Published: 9 May 2019
    8.8
    High

    CVE-2019-10127

    Last Modified: 21 Nov 2024

    A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files.

    Published: 9 May 2019
    4.3
    Medium

    CVE-2019-10130

    Last Modified: 21 Nov 2024

    A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.

    Published: 9 May 2019
    8.1
    High

    CVE-2019-5018

    Last Modified: 21 Nov 2024

    An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

    Published: 9 May 2019