CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-10128

    Last Modified: 21 Nov 2024

    A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.

    Published: 9 May 2019
    6.5
    Medium

    CVE-2019-10129

    Last Modified: 21 Nov 2024

    A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

    Published: 9 May 2019
    9.8
    Critical

    CVE-2019-7442

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

    Published: 8 May 2019
    5.5
    Medium

    CVE-2019-9698

    Last Modified: 21 Nov 2024

    Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulnerability that could allow an attacker to delete files on the resident system without elevated privileges.

    Published: 8 May 2019
    8.8
    High

    CVE-2019-8285

    Last Modified: 21 Nov 2024

    Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentially allow arbitrary code execution

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11398

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11406

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.

    Published: 8 May 2019
    7.5
    High

    CVE-2019-11458

    Last Modified: 15 Jan 2025

    An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-5021

    Last Modified: 21 Nov 2024

    Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11507

    Last Modified: 21 Nov 2024

    In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

    Published: 8 May 2019
    7.2
    High

    CVE-2019-11508

    Last Modified: 21 Nov 2024

    In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

    Published: 8 May 2019
    6.5
    Medium

    CVE-2019-5014

    Last Modified: 21 Nov 2024

    An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.

    Published: 8 May 2019
    5.5
    Medium

    CVE-2019-2053

    Last Modified: 21 Nov 2024

    In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-122074159

    Published: 8 May 2019
    7.5
    High

    CVE-2019-2052

    Last Modified: 21 Nov 2024

    In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117556606

    Published: 8 May 2019
    7.5
    High

    CVE-2019-2051

    Last Modified: 21 Nov 2024

    In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when processing a proxy auto config file with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117555811

    Published: 8 May 2019
    7.8
    High

    CVE-2019-2050

    Last Modified: 21 Nov 2024

    In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9 Android ID: A-121327323

    Published: 8 May 2019
    7.8
    High

    CVE-2019-2049

    Last Modified: 21 Nov 2024

    In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9 Android ID: A-120445479

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-2047

    Last Modified: 21 Nov 2024

    In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117607414

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-2046

    Last Modified: 21 Nov 2024

    In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117556220

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-2045

    Last Modified: 21 Nov 2024

    In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.1 Android-9 Android ID: A-117554758

    Published: 8 May 2019
    8.8
    High

    CVE-2019-2044

    Last Modified: 21 Nov 2024

    In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-123701862

    Published: 8 May 2019
    7.3
    High

    CVE-2019-2043

    Last Modified: 21 Nov 2024

    In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-120484087

    Published: 8 May 2019
    10
    Critical

    CVE-2019-11510

    Last Modified: 6 Nov 2025

    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

    Published: 8 May 2019
    5.9
    Medium

    CVE-2019-11550

    Last Modified: 21 Nov 2024

    Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

    Published: 8 May 2019
    5.9
    Medium

    CVE-2019-11561

    Last Modified: 21 Nov 2024

    The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11564

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a /protected/vendor/codeception/codeception/tests/data/app/view/index.php POST request.

    Published: 8 May 2019
    7.8
    High

    CVE-2019-11819

    Last Modified: 21 Nov 2024

    Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp) via the First Name or Last Name.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11818

    Last Modified: 21 Nov 2024

    Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/system/workplace/admin/accounts/user_new.jsp). This allows an attacker to insert arbitrary JavaScript as user input (First Name or Last Name), which will be executed whenever the affected snippet is loaded.

    Published: 8 May 2019
    8.8
    High

    CVE-2019-11642

    Last Modified: 21 Nov 2024

    A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can poison log files by entering malicious payloads in either headers or form elements. These payloads are then executed via a client side debugging console. This is predicated on the debugging console and Java Bean being made available to the deployed application.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11643

    Last Modified: 21 Nov 2024

    Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.

    Published: 8 May 2019
    7.4
    High

    CVE-2018-5408

    Last Modified: 21 Nov 2024

    The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not validate, or incorrectly validates, the PrinterLogic management portal's SSL certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.

    Published: 8 May 2019
    9.8
    Critical

    CVE-2018-5409

    Last Modified: 21 Nov 2024

    The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-9505

    Last Modified: 21 Nov 2024

    The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenticated attacker may be able to remotely execute arbitrary code with SYSTEM privileges.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-8349

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-8387

    Last Modified: 21 Nov 2024

    MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11814

    Last Modified: 21 Nov 2024

    An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11813

    Last Modified: 21 Nov 2024

    An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.

    Published: 8 May 2019
    6.1
    Medium

    CVE-2019-11812

    Last Modified: 21 Nov 2024

    A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.

    Published: 8 May 2019
    —
    Unknown

    CVE-2019-11824

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 May 2019
    6.8
    Medium

    CVE-2019-11098

    Last Modified: 21 Nov 2024

    Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

    Published: 8 May 2019
    8.1
    High

    CVE-2019-11815

    Last Modified: 21 Nov 2024

    An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.

    Published: 8 May 2019
    9.8
    Critical

    CVE-2019-10712

    Last Modified: 21 Nov 2024

    The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

    Published: 7 May 2019
    7.8
    High

    CVE-2018-6243

    Last Modified: 21 Nov 2024

    NVIDIA Tegra TLK Widevine Trust Application contains a vulnerability in which missing the input parameter checking of video metadata count may lead to Arbitrary Code Execution, Denial of Service or Escalation of Privileges. Android ID: A-72315075. Severity Rating: High. Version: N/A.

    Published: 7 May 2019
    9.8
    Critical

    CVE-2018-6634

    Last Modified: 21 Nov 2024

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access to an account.

    Published: 7 May 2019
    8.1
    High

    CVE-2019-7746

    Last Modified: 21 Nov 2024

    JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.

    Published: 7 May 2019
    9.8
    Critical

    CVE-2019-7745

    Last Modified: 21 Nov 2024

    JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key field.

    Published: 7 May 2019
    6.1
    Medium

    CVE-2019-7687

    Last Modified: 21 Nov 2024

    cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data.

    Published: 7 May 2019
    9.8
    Critical

    CVE-2019-7564

    Last Modified: 21 Nov 2024

    An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the password of the Wi-FI network.

    Published: 7 May 2019
    6.1
    Medium

    CVE-2019-7541

    Last Modified: 21 Nov 2024

    Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

    Published: 7 May 2019
    8.1
    High

    CVE-2019-7443

    Last Modified: 21 Nov 2024

    KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.

    Published: 7 May 2019