CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-11358

    Last Modified: 21 Nov 2024

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

    Published: 27 Mar 2019
    7.5
    High

    CVE-2019-0212

    Last Modified: 21 Nov 2024

    In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied to users of the HBase REST server. Requests sent to the HBase REST server were executed with the permissions of the REST server itself, not with the permissions of the end-user. This issue is only relevant when HBase is configured with Kerberos authentication, HBase authorization is enabled, and the REST server is configured with SPNEGO authentication. This issue does not extend beyond the HBase REST server.

    Published: 27 Mar 2019
    9.8
    Critical

    CVE-2019-10842

    Last Modified: 21 Nov 2024

    Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute arbitrary code on the target system. Note that there are three underscore characters in the cookie name. This is unrelated to the __cfduid cookie that is legitimately used by Cloudflare.

    Published: 27 Mar 2019
    9.8
    Critical

    CVE-2019-20933

    Last Modified: 21 Nov 2024

    InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

    Published: 27 Mar 2019
    5.3
    Medium

    CVE-2019-3829

    Last Modified: 21 Nov 2024

    A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.

    Published: 27 Mar 2019
    5.9
    Medium

    CVE-2019-3836

    Last Modified: 21 Nov 2024

    It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.

    Published: 27 Mar 2019
    4.8
    Medium

    CVE-2019-3847

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

    Published: 27 Mar 2019
    7.8
    High

    CVE-2018-12179

    Last Modified: 21 Nov 2024

    Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

    Published: 27 Mar 2019
    7.5
    High

    CVE-2019-0222

    Last Modified: 21 Nov 2024

    In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

    Published: 27 Mar 2019
    4.8
    Medium

    CVE-2019-1571

    Last Modified: 21 Nov 2024

    The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.

    Published: 26 Mar 2019
    5.4
    Medium

    CVE-2019-10107

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -> My Account" section.

    Published: 26 Mar 2019
    5.4
    Medium

    CVE-2019-10106

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action to the "Site Admin Settings - News module" section.

    Published: 26 Mar 2019
    5.4
    Medium

    CVE-2019-10105

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a "Create a new Template" action to the Design Manager.

    Published: 26 Mar 2019
    7.5
    High

    CVE-2019-1572

    Last Modified: 21 Nov 2024

    PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.

    Published: 26 Mar 2019
    4.8
    Medium

    CVE-2019-1570

    Last Modified: 21 Nov 2024

    The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.

    Published: 26 Mar 2019
    4.8
    Medium

    CVE-2019-1569

    Last Modified: 21 Nov 2024

    The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.

    Published: 26 Mar 2019
    9.1
    Critical

    CVE-2019-6569

    Last Modified: 21 Nov 2024

    The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into the mirrored network. An attacker could use this behavior to transmit malicious packets to systems in the mirrored network, possibly influencing their configuration and runtime behavior.

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-9743

    Last Modified: 21 Nov 2024

    An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-9744

    Last Modified: 21 Nov 2024

    An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.

    Published: 26 Mar 2019
    5.5
    Medium

    CVE-2018-15817

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.

    Published: 26 Mar 2019
    5.5
    Medium

    CVE-2018-15816

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.

    Published: 26 Mar 2019
    5.5
    Medium

    CVE-2018-15815

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.

    Published: 26 Mar 2019
    5.5
    Medium

    CVE-2018-15814

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.

    Published: 26 Mar 2019
    5.5
    Medium

    CVE-2018-15813

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.

    Published: 26 Mar 2019
    6.1
    Medium

    CVE-2019-9961

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 26 Mar 2019
    5.4
    Medium

    CVE-2019-6341

    Last Modified: 21 Nov 2024

    In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

    Published: 26 Mar 2019
    4.3
    Medium

    CVE-2019-8989

    Last Modified: 21 Nov 2024

    The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

    Published: 26 Mar 2019
    8.1
    High

    CVE-2019-8988

    Last Modified: 21 Nov 2024

    The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site contains a vulnerability that theoretically allows a user to escalate their privileges on the affected system, in a way that may allow for data modifications and deletions that should be denied. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

    Published: 26 Mar 2019
    5.4
    Medium

    CVE-2019-8987

    Last Modified: 21 Nov 2024

    The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a persistent cross-site scripting vulnerability that theoretically allows an authenticated user to gain access to all the capabilities of the web interface available to more privileged users. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

    Published: 26 Mar 2019
    6.5
    Medium

    CVE-2019-6540

    Last Modified: 22 May 2025

    The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD, Primo ICD, Protecta ICD and CRT-D, Secura ICD, Virtuoso ICD, Virtuoso II ICD, Visia AF ICD, and Viva CRT-D does not implement encryption. An attacker with adjacent short-range access to a target product can listen to communications, including the transmission of sensitive data.

    Published: 26 Mar 2019
    4.3
    Medium

    CVE-2019-3852

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

    Published: 26 Mar 2019
    4.3
    Medium

    CVE-2019-3851

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

    Published: 26 Mar 2019
    4.3
    Medium

    CVE-2019-3850

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-3849

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

    Published: 26 Mar 2019
    —
    Unknown

    CVE-2017-2660

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific product, protocol, or design, that falls into the scope of the assigning CNA. Notes: None

    Published: 26 Mar 2019
    9.8
    Critical

    CVE-2019-10068

    Last Modified: 19 Dec 2025

    An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

    Published: 26 Mar 2019
    9.8
    Critical

    CVE-2010-5305

    Last Modified: 26 Jun 2025

    The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain access to the product and allow changes to the product’s configuration or program. When applicable, upgrade product firmware to a version that includes enhanced security functionality compatible with Rockwell Automation's FactoryTalk Security services.

    Published: 26 Mar 2019
    7.7
    High

    CVE-2019-3606

    Last Modified: 21 Nov 2024

    Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrators to view configuration information in plain text format via the GUI or GUI terminal commands.

    Published: 26 Mar 2019
    6.5
    Medium

    CVE-2019-3597

    Last Modified: 21 Nov 2024

    Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect handling of expired GUI sessions.

    Published: 26 Mar 2019
    7.5
    High

    CVE-2013-2805

    Last Modified: 21 Nov 2024

    Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receives a datagram with an incorrect value in the “Record Data Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to an oversized value, an attacker could cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to this vulnerability can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-9061

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it is possible to reach an unserialize call with untrusted input and achieve authenticated object injection by using the "install module" feature.

    Published: 26 Mar 2019
    7.5
    High

    CVE-2013-2806

    Last Modified: 21 Nov 2024

    Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “End of Current Record” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size.” Then the service will calculate an incorrect value for the “End of Current Record” field causing access violations that lead to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation security advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

    Published: 26 Mar 2019
    7.2
    High

    CVE-2019-9059

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. It is possible, with an administrator account, to achieve command injection by modifying the path of the e-mail executable in Mail Settings, setting "sendmail" in the "Mailer" option, and launching the "Forgot your password" feature.

    Published: 26 Mar 2019
    7.2
    High

    CVE-2019-9058

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated object injection.

    Published: 26 Mar 2019
    7.5
    High

    CVE-2013-2807

    Last Modified: 21 Nov 2024

    Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size” that will cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-9057

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call with an untrusted parameter, and achieve authenticated object injection.

    Published: 26 Mar 2019
    8.8
    High

    CVE-2019-9055

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. In the module DesignManager (in the files action.admin_bulk_css.php and action.admin_bulk_template.php), with an unprivileged user with Designer permission, it is possible reach an unserialize call with a crafted value in the m1_allparms parameter, and achieve object injection.

    Published: 26 Mar 2019
    9.8
    Critical

    CVE-2014-5401

    Last Modified: 3 Nov 2025

    Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.

    Published: 26 Mar 2019
    8.1
    High

    CVE-2019-9053

    Last Modified: 17 Nov 2025

    An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve unauthenticated blind time-based SQL injection via the m1_idlist parameter.

    Published: 26 Mar 2019
    7.5
    High

    CVE-2018-19856

    Last Modified: 21 Nov 2024

    GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.

    Published: 26 Mar 2019