CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-9621

    Last Modified: 4 Nov 2025

    Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

    Published: 30 Apr 2019
    7
    High

    CVE-2018-19374

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.

    Published: 30 Apr 2019
    4.7
    Medium

    CVE-2019-3805

    Last Modified: 21 Nov 2024

    A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-3894

    Last Modified: 21 Nov 2024

    It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. This could allow a shared thread to use the wrong security identity when executing.

    Published: 30 Apr 2019
    7.3
    High

    CVE-2019-5624

    Last Modified: 21 Nov 2024

    Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at the privilege level of the user running Metasploit. This issue affects: Rapid7 Metasploit Framework version 4.14.0 and prior versions.

    Published: 30 Apr 2019
    9.8
    Critical

    CVE-2019-10950

    Last Modified: 21 Nov 2024

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerability may be able to access the underlying operating system.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-10948

    Last Modified: 21 Nov 2024

    Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X are susceptible to a denial-of-service condition as a result of an overflow of TCP packets, which requires the device to be manually rebooted.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-3399

    Last Modified: 21 Nov 2024

    The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check.

    Published: 30 Apr 2019
    5.4
    Medium

    CVE-2018-20239

    Last Modified: 21 Nov 2024

    Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0.

    Published: 30 Apr 2019
    6.1
    Medium

    CVE-2019-4166

    Last Modified: 21 Nov 2024

    IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 158699.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-6494

    Last Modified: 21 Nov 2024

    IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user defined string to a file; that file will be promptly deleted regardless of access controls.

    Published: 30 Apr 2019
    6.1
    Medium

    CVE-2015-9286

    Last Modified: 21 Nov 2024

    Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10316

    Last Modified: 21 Nov 2024

    Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 30 Apr 2019
    5.9
    Medium

    CVE-2019-10317

    Last Modified: 21 Nov 2024

    Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10318

    Last Modified: 21 Nov 2024

    Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master where it could be viewed by users with access to the master file system.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-10307

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers to change the per-job default graph configuration for all users.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10311

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 30 Apr 2019
    4.3
    Medium

    CVE-2019-10312

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10313

    Last Modified: 21 Nov 2024

    Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 30 Apr 2019
    5.9
    Medium

    CVE-2019-10314

    Last Modified: 21 Nov 2024

    Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10315

    Last Modified: 21 Nov 2024

    Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.

    Published: 30 Apr 2019
    9.3
    Critical

    CVE-2019-10309

    Last Modified: 21 Nov 2024

    Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbitrary files from Swarm clients.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-10308

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration for all users.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-5825

    Last Modified: 24 Oct 2025

    Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11494

    Last Modified: 21 Nov 2024

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.

    Published: 30 Apr 2019
    6.5
    Medium

    CVE-2019-5826

    Last Modified: 21 Nov 2024

    Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-5827

    Last Modified: 21 Nov 2024

    Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-11499

    Last Modified: 21 Nov 2024

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-5824

    Last Modified: 21 Nov 2024

    Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 30 Apr 2019
    7.5
    High

    CVE-2019-0194

    Last Modified: 21 Nov 2024

    Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsupported Camel 2.x (2.19 and earlier) versions may be also affected.

    Published: 30 Apr 2019
    7.1
    High

    CVE-2019-10131

    Last Modified: 21 Nov 2024

    An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.

    Published: 30 Apr 2019
    8.8
    High

    CVE-2019-10310

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins

    Published: 30 Apr 2019
    4.3
    Medium

    CVE-2019-4047

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest user, and obtain the information of the server execution. IBM X-Force ID: 156243.

    Published: 29 Apr 2019
    5.9
    Medium

    CVE-2018-2007

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.

    Published: 29 Apr 2019
    5.4
    Medium

    CVE-2018-2004

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 155006.

    Published: 29 Apr 2019
    5.3
    Medium

    CVE-2018-1961

    Last Modified: 21 Nov 2024

    IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages. IBM X-Force ID: 153657.

    Published: 29 Apr 2019
    8.8
    High

    CVE-2019-3493

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all versions. The vulnerability could be remotely exploited to Remote Code Execution.

    Published: 29 Apr 2019
    8.8
    High

    CVE-2018-5123

    Last Modified: 21 Nov 2024

    A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in all Bugzilla versions prior to 4.4.

    Published: 29 Apr 2019
    9.8
    Critical

    CVE-2019-3561

    Last Modified: 21 Nov 2024

    Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).

    Published: 29 Apr 2019
    6.1
    Medium

    CVE-2019-3562

    Last Modified: 21 Nov 2024

    A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.

    Published: 29 Apr 2019
    9.8
    Critical

    CVE-2019-3563

    Last Modified: 21 Nov 2024

    Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00

    Published: 29 Apr 2019
    7
    High

    CVE-2019-8454

    Last Modified: 21 Nov 2024

    A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.

    Published: 29 Apr 2019
    9
    Critical

    CVE-2019-11595

    Last Modified: 21 Nov 2024

    In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

    Published: 29 Apr 2019
    8.1
    High

    CVE-2019-11594

    Last Modified: 21 Nov 2024

    In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

    Published: 29 Apr 2019
    8.1
    High

    CVE-2019-11593

    Last Modified: 21 Nov 2024

    In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

    Published: 29 Apr 2019
    7.8
    High

    CVE-2019-5429

    Last Modified: 21 Nov 2024

    Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

    Published: 29 Apr 2019
    7.5
    High

    CVE-2019-5492

    Last Modified: 21 Nov 2024

    Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.

    Published: 29 Apr 2019
    6.1
    Medium

    CVE-2019-11592

    Last Modified: 21 Nov 2024

    WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.

    Published: 29 Apr 2019
    6.1
    Medium

    CVE-2015-9285

    Last Modified: 21 Nov 2024

    esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.

    Published: 29 Apr 2019
    9.8
    Critical

    CVE-2016-10749

    Last Modified: 22 Jul 2025

    parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.

    Published: 29 Apr 2019