CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-2038

    Last Modified: 21 Nov 2024

    In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-121259048.

    Published: 19 Apr 2019
    7.8
    High

    CVE-2019-2035

    Last Modified: 21 Nov 2024

    In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-122320256

    Published: 19 Apr 2019
    7.8
    High

    CVE-2019-2034

    Last Modified: 21 Nov 2024

    In rw_i93_sm_read_ndef of rw_i93.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the NFC process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-122035770.

    Published: 19 Apr 2019
    7.8
    High

    CVE-2019-2033

    Last Modified: 21 Nov 2024

    In create_hdr of dnssd_clientstub.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-121327565.

    Published: 19 Apr 2019
    7.8
    High

    CVE-2019-2031

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120502559.

    Published: 19 Apr 2019
    9.8
    Critical

    CVE-2019-2030

    Last Modified: 21 Nov 2024

    In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-119496789.

    Published: 19 Apr 2019
    8.8
    High

    CVE-2019-2028

    Last Modified: 21 Nov 2024

    In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120644655.

    Published: 19 Apr 2019
    8.8
    High

    CVE-2019-2027

    Last Modified: 21 Nov 2024

    In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-119120561.

    Published: 19 Apr 2019
    7.8
    High

    CVE-2019-2026

    Last Modified: 21 Nov 2024

    In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission check. This could lead to local escalation of privilege and FRP bypass with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0Android ID: A-120866126

    Published: 19 Apr 2019
    6.1
    Medium

    CVE-2019-9841

    Last Modified: 21 Nov 2024

    Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.

    Published: 19 Apr 2019
    9.8
    Critical

    CVE-2019-11344

    Last Modified: 21 Nov 2024

    data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because only certain PHP-related filename extensions are blocked.

    Published: 19 Apr 2019
    5.9
    Medium

    CVE-2019-10886

    Last Modified: 21 Nov 2024

    An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (for the X7500D TV and other applicable TVs). This vulnerability allows an attacker to read arbitrary files without authentication over HTTP when Photo Sharing Plus application is running. This may allow an attacker to browse a particular directory (e.g. images) inside the private network.

    Published: 19 Apr 2019
    7.5
    High

    CVE-2019-4055

    Last Modified: 21 Nov 2024

    IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service attack within the TLS key renegotiation function. IBM X-Force ID: 156564.

    Published: 19 Apr 2019
    5.3
    Medium

    CVE-2018-1729

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 147708.

    Published: 19 Apr 2019
    7.5
    High

    CVE-2019-10245

    Last Modified: 21 Nov 2024

    In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.

    Published: 19 Apr 2019
    5.9
    Medium

    CVE-2019-11340

    Last Modified: 21 Nov 2024

    util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on [email protected]@good.example.com returns the [email protected] substring.

    Published: 19 Apr 2019
    7
    High

    CVE-2019-11599

    Last Modified: 21 Nov 2024

    The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a race condition with mmget_not_zero or get_task_mm calls. This is related to fs/userfaultfd.c, mm/mmap.c, fs/proc/task_mmu.c, and drivers/infiniband/core/uverbs_main.c.

    Published: 19 Apr 2019
    8.8
    High

    CVE-2019-11339

    Last Modified: 21 Nov 2024

    The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via crafted MPEG-4 video data.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-11338

    Last Modified: 21 Nov 2024

    libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-11332

    Last Modified: 21 Nov 2024

    MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456.

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-9161

    Last Modified: 21 Nov 2024

    WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password. (The password for root is the WebUI admin password concatenated with a static string.)

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-9160

    Last Modified: 21 Nov 2024

    WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (because the password for root is the WebUI admin password concatenated with a static string).

    Published: 18 Apr 2019
    6.8
    Medium

    CVE-2019-11015

    Last Modified: 21 Nov 2024

    A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based authentication via the Wallpaper Carousel application to obtain sensitive Clipboard data and the user's stored credentials (partially). This occurs because of paste access to a social media login page.

    Published: 18 Apr 2019
    8
    High

    CVE-2019-3719

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-3718

    Last Modified: 21 Nov 2024

    Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.

    Published: 18 Apr 2019
    4.8
    Medium

    CVE-2019-10893

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.

    Published: 18 Apr 2019
    5.9
    Medium

    CVE-2018-20200

    Last Modified: 21 Nov 2024

    CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967

    Published: 18 Apr 2019
    6.1
    Medium

    CVE-2019-11084

    Last Modified: 21 Nov 2024

    GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies.

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2019-9005

    Last Modified: 21 Nov 2024

    The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.

    Published: 18 Apr 2019
    4.8
    Medium

    CVE-2019-11017

    Last Modified: 21 Nov 2024

    On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2018-17289

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter.

    Published: 18 Apr 2019
    5.4
    Medium

    CVE-2018-17288

    Last Modified: 21 Nov 2024

    Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Filename" field in /Kofax/KFS/ThinClient/document/upload/ - (Thin Client) or (2) "DeviceName" field in /Kofax/KFS/Admin/DeviceService/device/ - (Administration Console).

    Published: 18 Apr 2019
    4.9
    Medium

    CVE-2018-17287

    Last Modified: 21 Nov 2024

    In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue operation.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-3398

    Last Modified: 24 Oct 2025

    Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability.

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-11223

    Last Modified: 21 Nov 2024

    An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

    Published: 18 Apr 2019
    8
    High

    CVE-2019-10300

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-10302

    Last Modified: 21 Nov 2024

    Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-10303

    Last Modified: 21 Nov 2024

    Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2019-10304

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers to initiate a connection to an attacker-specified server.

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2019-10305

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

    Published: 18 Apr 2019
    9.9
    Critical

    CVE-2019-10306

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbitrary code on the Jenkins master JVM.

    Published: 18 Apr 2019
    8.8
    High

    CVE-2019-10301

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 18 Apr 2019
    7.5
    High

    CVE-2019-8999

    Last Modified: 21 Nov 2024

    An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account.

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-11322

    Last Modified: 21 Nov 2024

    An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.

    Published: 18 Apr 2019
    5.3
    Medium

    CVE-2019-11321

    Last Modified: 21 Nov 2024

    An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-11320

    Last Modified: 21 Nov 2024

    In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrated by the 192.168.51.1 address.

    Published: 18 Apr 2019
    9.8
    Critical

    CVE-2019-11319

    Last Modified: 21 Nov 2024

    An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2018-17168

    Last Modified: 21 Nov 2024

    PrinterOn Enterprise 4.1.4 contains multiple Cross Site Request Forgery (CSRF) vulnerabilities in the Administration page. For example, an administrator, by following a link, can be tricked into making unwanted changes to a printer (Disable, Approve, etc).

    Published: 18 Apr 2019
    6.5
    Medium

    CVE-2019-1841

    Last Modified: 23 Jul 2025

    A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.

    Published: 18 Apr 2019
    5.3
    Medium

    CVE-2019-1837

    Last Modified: 21 Nov 2024

    A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The vulnerability is due to improper validation of input parameters in the UDS API requests. An attacker could exploit this vulnerability by sending a crafted request to the UDS API of an affected device. A successful exploit could allow the attacker to make the A Cisco DB service quit unexpectedly, preventing admin access to the Unified CM management GUI. Manual intervention may be required to restore normal operation. Software versions 10.5, 11.5, 12.0, 12.5 are affected.

    Published: 18 Apr 2019