CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2018-19113

    Last Modified: 21 Nov 2024

    The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2019-3489

    Last Modified: 21 Nov 2024

    An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2019-6715

    Last Modified: 21 Nov 2024

    pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

    Published: 1 Apr 2019
    7.8
    High

    CVE-2018-4050

    Last Modified: 21 Nov 2024

    An exploitable local privilege escalation vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can globally adjust folder permissions leading to execution of arbitrary code with elevated privileges.

    Published: 1 Apr 2019
    9.8
    Critical

    CVE-2019-5523

    Last Modified: 21 Nov 2024

    VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged in session.

    Published: 1 Apr 2019
    8.8
    High

    CVE-2019-9132

    Last Modified: 21 Nov 2024

    Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower.

    Published: 1 Apr 2019
    10
    Critical

    CVE-2019-10686

    Last Modified: 21 Nov 2024

    An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intranet port scan or raise a GET request via /system-info/health because the %23 substring is mishandled.

    Published: 1 Apr 2019
    8.8
    High

    CVE-2018-5757

    Last Modified: 21 Nov 2024

    An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.

    Published: 1 Apr 2019
    9.8
    Critical

    CVE-2019-10684

    Last Modified: 21 Nov 2024

    Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.

    Published: 1 Apr 2019
    9.8
    Critical

    CVE-2019-5891

    Last Modified: 21 Nov 2024

    An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application.

    Published: 1 Apr 2019
    8.8
    High

    CVE-2019-5890

    Last Modified: 21 Nov 2024

    An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2019-5889

    Last Modified: 21 Nov 2024

    An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.

    Published: 1 Apr 2019
    6.1
    Medium

    CVE-2019-5888

    Last Modified: 21 Nov 2024

    Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13299

    Last Modified: 21 Nov 2024

    Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.

    Published: 1 Apr 2019
    4.2
    Medium

    CVE-2018-13298

    Last Modified: 21 Nov 2024

    Channel accessible by non-endpoint vulnerability in privacy page in Synology Android Moments before 1.2.3-199 allows man-in-the-middle attackers to execute arbitrary code via unspecified vectors.

    Published: 1 Apr 2019
    5.3
    Medium

    CVE-2018-13297

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2018-13296

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption vulnerability in TLS configuration in Synology MailPlus Server before 2.0.5-0606 allows remote attackers to conduct denial-of-service attacks via client-initiated renegotiation.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13295

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.Personal.Application.Info in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the version parameter.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13294

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.Personal.Profile in Synology Application Service before 1.5.4-0320 allows remote authenticated users to obtain sensitive system information via the uid parameter.

    Published: 1 Apr 2019
    5.9
    Medium

    CVE-2018-13293

    Last Modified: 14 Jan 2025

    Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13291

    Last Modified: 14 Jan 2025

    Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13292

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.

    Published: 1 Apr 2019
    4.3
    Medium

    CVE-2018-13290

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.

    Published: 1 Apr 2019
    5.3
    Medium

    CVE-2018-13289

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.

    Published: 1 Apr 2019
    5.3
    Medium

    CVE-2018-13288

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in SYNO.FolderSharing.List in Synology File Station before 1.2.3-0252 and before 1.1.5-0125 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.

    Published: 1 Apr 2019
    6.5
    Medium

    CVE-2018-13287

    Last Modified: 21 Nov 2024

    Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2018-13285

    Last Modified: 21 Nov 2024

    Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

    Published: 1 Apr 2019
    6.5
    Medium

    CVE-2018-13286

    Last Modified: 14 Jan 2025

    Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2018-13284

    Last Modified: 14 Jan 2025

    Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

    Published: 1 Apr 2019
    8.8
    High

    CVE-2018-13283

    Last Modified: 21 Nov 2024

    Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.

    Published: 1 Apr 2019
    7.1
    High

    CVE-2017-16775

    Last Modified: 21 Nov 2024

    Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 1 Apr 2019
    6.5
    Medium

    CVE-2017-16774

    Last Modified: 14 Jan 2025

    Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.

    Published: 1 Apr 2019
    7.1
    High

    CVE-2018-8913

    Last Modified: 21 Nov 2024

    Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL.

    Published: 1 Apr 2019
    7.8
    High

    CVE-2019-0211

    Last Modified: 27 Oct 2025

    In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2019-0215

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.

    Published: 1 Apr 2019
    5.3
    Medium

    CVE-2019-0220

    Last Modified: 21 Nov 2024

    A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly collapse them.

    Published: 1 Apr 2019
    6.5
    Medium

    CVE-2019-10873

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

    Published: 1 Apr 2019
    5.3
    Medium

    CVE-2019-0196

    Last Modified: 21 Nov 2024

    A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.

    Published: 1 Apr 2019
    7.5
    High

    CVE-2019-0217

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.

    Published: 1 Apr 2019
    8.8
    High

    CVE-2014-7198

    Last Modified: 21 Nov 2024

    OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

    Published: 31 Mar 2019
    7.5
    High

    CVE-2019-10678

    Last Modified: 21 Nov 2024

    Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.

    Published: 31 Mar 2019
    —
    Unknown

    CVE-2019-10675

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 Mar 2019
    9.8
    Critical

    CVE-2019-10672

    Last Modified: 21 Nov 2024

    treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.

    Published: 31 Mar 2019
    9.8
    Critical

    CVE-2019-10664

    Last Modified: 21 Nov 2024

    Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.

    Published: 31 Mar 2019
    8.8
    High

    CVE-2019-10663

    Last Modified: 21 Nov 2024

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10662

    Last Modified: 21 Nov 2024

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.

    Published: 30 Mar 2019
    9.8
    Critical

    CVE-2019-10661

    Last Modified: 21 Nov 2024

    On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10660

    Last Modified: 21 Nov 2024

    Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10659

    Last Modified: 21 Nov 2024

    Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10658

    Last Modified: 21 Nov 2024

    Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.

    Published: 30 Mar 2019