CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-10657

    Last Modified: 21 Nov 2024

    Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10656

    Last Modified: 21 Nov 2024

    Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.

    Published: 30 Mar 2019
    9.8
    Critical

    CVE-2019-10655

    Last Modified: 21 Nov 2024

    Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.

    Published: 30 Mar 2019
    5.5
    Medium

    CVE-2019-10654

    Last Modified: 21 Nov 2024

    The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive, a different vulnerability than CVE-2017-8845.

    Published: 30 Mar 2019
    7.2
    High

    CVE-2019-10652

    Last Modified: 21 Nov 2024

    An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.

    Published: 30 Mar 2019
    9.8
    Critical

    CVE-2019-10648

    Last Modified: 22 Dec 2025

    Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.

    Published: 30 Mar 2019
    9.8
    Critical

    CVE-2019-10647

    Last Modified: 21 Nov 2024

    ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).

    Published: 30 Mar 2019
    6.1
    Medium

    CVE-2019-10646

    Last Modified: 21 Nov 2024

    Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.

    Published: 30 Mar 2019
    8.8
    High

    CVE-2019-10644

    Last Modified: 21 Nov 2024

    An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.

    Published: 30 Mar 2019
    9.8
    Critical

    CVE-2018-18766

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.

    Published: 29 Mar 2019
    6.1
    Medium

    CVE-2018-19201

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability in the ModCP Profile Editor in MyBB before 1.8.20 allows remote attackers to inject JavaScript via the 'username' parameter.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2018-15840

    Last Modified: 21 Nov 2024

    TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2018-20378

    Last Modified: 21 Nov 2024

    The L2CAP signaling channel implementation and SDP server implementation in OpenSynergy Blue SDK 3.2 through 6.0 allow remote, unauthenticated attackers to execute arbitrary code or cause a denial of service via malicious L2CAP configuration requests, in conjunction with crafted SDP communication over maliciously configured L2CAP channels. The attacker must have connectivity over the Bluetooth physical layer, and must be able to send raw L2CAP frames. This is related to L2Cap_HandleConfigReq in core/stack/l2cap/l2cap_sm.c and SdpServHandleServiceSearchAttribReq in core/stack/sdp/sdpserv.c.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2019-9922

    Last Modified: 21 Nov 2024

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.

    Published: 29 Mar 2019
    6.5
    Medium

    CVE-2019-9921

    Last Modified: 21 Nov 2024

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.

    Published: 29 Mar 2019
    8.8
    High

    CVE-2019-9920

    Last Modified: 21 Nov 2024

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.

    Published: 29 Mar 2019
    5.4
    Medium

    CVE-2019-9919

    Last Modified: 21 Nov 2024

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.

    Published: 29 Mar 2019
    9.1
    Critical

    CVE-2019-9918

    Last Modified: 21 Nov 2024

    An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.

    Published: 29 Mar 2019
    8.7
    High

    CVE-2017-18111

    Last Modified: 21 Nov 2024

    The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe internal network resources by requesting internal locations, read the contents of files and also cause an out of memory exception affecting availability via an XML External Entity vulnerability.

    Published: 29 Mar 2019
    6.5
    Medium

    CVE-2017-18110

    Last Modified: 21 Nov 2024

    The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.

    Published: 29 Mar 2019
    6.1
    Medium

    CVE-2017-18109

    Last Modified: 21 Nov 2024

    The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

    Published: 29 Mar 2019
    7.2
    High

    CVE-2017-18108

    Last Modified: 21 Nov 2024

    The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2017-18106

    Last Modified: 21 Nov 2024

    The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash.

    Published: 29 Mar 2019
    8.1
    High

    CVE-2017-18105

    Last Modified: 21 Nov 2024

    The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability.

    Published: 29 Mar 2019
    8.8
    High

    CVE-2019-9604

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile actions.

    Published: 29 Mar 2019
    5.4
    Medium

    CVE-2019-9605

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in a .ico picture upload.

    Published: 29 Mar 2019
    6.8
    Medium

    CVE-2019-9695

    Last Modified: 21 Nov 2024

    Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or code on a target machine or in a target process. Note that this exploit is only possible with direct physical access to the device.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2019-6481

    Last Modified: 21 Nov 2024

    Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would require the user to accept a second-factor request in a mobile app." approach, related to a "Multifactor Auth Bypass, Full Disk Encryption Bypass" issue affecting the Affected Chrome Plugin component.

    Published: 29 Mar 2019
    7.5
    High

    CVE-2019-10477

    Last Modified: 21 Nov 2024

    The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions.

    Published: 29 Mar 2019
    9.8
    Critical

    CVE-2019-10276

    Last Modified: 21 Nov 2024

    Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.

    Published: 29 Mar 2019
    9.8
    Critical

    CVE-2019-10269

    Last Modified: 21 Nov 2024

    BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.

    Published: 29 Mar 2019
    8.8
    High

    CVE-2019-20393

    Last Modified: 21 Nov 2024

    A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.

    Published: 29 Mar 2019
    5.4
    Medium

    CVE-2019-3884

    Last Modified: 21 Nov 2024

    A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

    Published: 29 Mar 2019
    6.5
    Medium

    CVE-2019-20396

    Last Modified: 21 Nov 2024

    A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsing.

    Published: 29 Mar 2019
    9.8
    Critical

    CVE-2019-10262

    Last Modified: 21 Nov 2024

    A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.

    Published: 28 Mar 2019
    7.5
    High

    CVE-2019-0225

    Last Modified: 21 Nov 2024

    A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.

    Published: 28 Mar 2019
    6.1
    Medium

    CVE-2019-0224

    Last Modified: 21 Nov 2024

    In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

    Published: 28 Mar 2019
    5.9
    Medium

    CVE-2019-6608

    Last Modified: 21 Nov 2024

    On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon may leak memory on a multi-blade BIG-IP vCMP guest when processing authorized SNMP requests.

    Published: 28 Mar 2019
    6.8
    Medium

    CVE-2019-6607

    Last Modified: 21 Nov 2024

    On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which results in code execution as the admin user.

    Published: 28 Mar 2019
    4.3
    Medium

    CVE-2019-6606

    Last Modified: 21 Nov 2024

    On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests with a request-id of 0, the snmpd process may leak a small amount of memory.

    Published: 28 Mar 2019
    6.8
    Medium

    CVE-2019-6604

    Last Modified: 21 Nov 2024

    On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed Bridge.

    Published: 28 Mar 2019
    7.5
    High

    CVE-2019-6605

    Last Modified: 21 Nov 2024

    On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server and processed by an associated Client SSL or Server SSL profile may cause a denial of service.

    Published: 28 Mar 2019
    7.5
    High

    CVE-2019-6603

    Last Modified: 21 Nov 2024

    In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent to a self IP address or a FastL4 virtual server may cause an interruption of service. The control plane is not exposed to this issue. This issue impacts the data plane virtual servers and self IPs.

    Published: 28 Mar 2019
    7.5
    High

    CVE-2019-6602

    Last Modified: 21 Nov 2024

    In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices when handling a malicious request.

    Published: 28 Mar 2019
    6.1
    Medium

    CVE-2019-9167

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.

    Published: 28 Mar 2019
    7.8
    High

    CVE-2019-9166

    Last Modified: 21 Nov 2024

    Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.

    Published: 28 Mar 2019
    9.8
    Critical

    CVE-2019-9165

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

    Published: 28 Mar 2019
    8.8
    High

    CVE-2019-9202

    Last Modified: 21 Nov 2024

    Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.

    Published: 28 Mar 2019
    9.8
    Critical

    CVE-2019-9203

    Last Modified: 21 Nov 2024

    Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.

    Published: 28 Mar 2019
    9.8
    Critical

    CVE-2019-9204

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.

    Published: 28 Mar 2019