CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-11627

    Last Modified: 21 Nov 2024

    gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-0214

    Last Modified: 21 Nov 2024

    In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-0213

    Last Modified: 21 Nov 2024

    In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerability is considered as minor risk, as only users with admin role can change the configuration, or the communication between the browser and the Archiva server must be compromised.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3939

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.

    Published: 30 Apr 2019
    7.8
    High

    CVE-2019-3938

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc binary. The same binary can be used to decrypt any configuration file since all the encryption logic is hard coded. A local attacker can use this vulnerability to gain access to devices username and passwords.

    Published: 30 Apr 2019
    7.8
    High

    CVE-2019-3937

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sensitive data.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-3936

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state. A remote, unauthenticated attacker can use this vulnerability to stop an active slideshow.

    Published: 30 Apr 2019
    9.1
    Critical

    CVE-2019-3935

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active slideshows.

    Published: 30 Apr 2019
    5.3
    Medium

    CVE-2019-3934

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the current slide image without knowing the access code.

    Published: 30 Apr 2019
    5.3
    Medium

    CVE-2019-3933

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this vulnerability to watch a slideshow without knowing the access code.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3932

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-3931

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3930

    Last Modified: 21 Nov 2024

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3929

    Last Modified: 3 Nov 2025

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

    Published: 30 Apr 2019
    5.3
    Medium

    CVE-2019-3928

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.100.3.2.7.4 OIDs. A remote, unauthenticated attacker can use this vulnerability to access a restricted presentation or to become the presenter.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3927

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3926

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-3925

    Last Modified: 21 Nov 2024

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

    Published: 30 Apr 2019
    5.3
    Medium

    CVE-2019-11626

    Last Modified: 21 Nov 2024

    routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/index.php?uri=1234%5c request.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11625

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to manage emailing) could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11624

    Last Modified: 21 Nov 2024

    doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote background administrator privilege user can exploit this vulnerability to delete arbitrary files.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11623

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb. A remote background administrator privilege user (or a user with permission to manage configuration siteweb) could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11622

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_edit_titre.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11621

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a user with permission to manage network configuration) could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11620

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information via modulecategory_add_titre.

    Published: 30 Apr 2019
    4.9
    Medium

    CVE-2019-11619

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or a user with permission to manage configuration analytics) could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-11618

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XRXhlF30UaGe1g3cZY6i1K9 access_token in a uri=blog&action=index&controller=blog action to /api/index.php.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-11617

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exploit this vulnerability for "Google Analytics code" modification.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-11616

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php. A remote unauthenticated attacker could exploit this vulnerability to obtain the administrator password.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-11615

    Last Modified: 21 Nov 2024

    /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can use this vulnerability to upload backdoor files to control the server.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11614

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-11613

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered user could exploit the vulnerability to obtain database sensitive information.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11612

    Last Modified: 21 Nov 2024

    doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attacker can exploit this vulnerability to delete arbitrary files.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11611

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11610

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

    Published: 30 Apr 2019
    8.2
    High

    CVE-2019-11609

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information or make the server unserviceable.

    Published: 30 Apr 2019
    8.2
    High

    CVE-2019-11608

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information or make the server unserviceable.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11607

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11606

    Last Modified: 21 Nov 2024

    doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2018-14930

    Last Modified: 21 Nov 2024

    An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2018-14874

    Last Modified: 21 Nov 2024

    An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries, allowing SQL injection with an authenticated session.

    Published: 30 Apr 2019
    5.4
    Medium

    CVE-2018-14875

    Last Modified: 21 Nov 2024

    An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.

    Published: 30 Apr 2019
    6.1
    Medium

    CVE-2018-14931

    Last Modified: 21 Nov 2024

    An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2018-15208

    Last Modified: 21 Nov 2024

    BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.

    Published: 30 Apr 2019
    7.2
    High

    CVE-2018-15207

    Last Modified: 21 Nov 2024

    BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2018-15206

    Last Modified: 21 Nov 2024

    BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.

    Published: 30 Apr 2019
    6.1
    Medium

    CVE-2019-11193

    Last Modified: 16 Dec 2025

    The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-9486

    Last Modified: 21 Nov 2024

    STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2018-20835

    Last Modified: 21 Nov 2024

    A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

    Published: 30 Apr 2019
    6.1
    Medium

    CVE-2019-10272

    Last Modified: 21 Nov 2024

    An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isintervenor parameter, as demonstrated by the %0aSet-cookie: substring.

    Published: 30 Apr 2019