CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2018-17494

    Last Modified: 21 Nov 2024

    eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual Keyboard Start Menu. By visiting the kiosk and pressing windows key twice, an attacker could exploit this vulnerability to close the program and launch other processes on the system.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17493

    Last Modified: 21 Nov 2024

    eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Fullscreen button. By visiting the kiosk and clicking the full screen button in the bottom right, an attacker could exploit this vulnerability to close the program and launch other processes on the system.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17492

    Last Modified: 21 Nov 2024

    EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17491

    Last Modified: 21 Nov 2024

    EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer.

    Published: 19 Mar 2019
    7.7
    High

    CVE-2018-17490

    Last Modified: 21 Nov 2024

    EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.

    Published: 19 Mar 2019
    2.9
    Low

    CVE-2018-17489

    Last Modified: 21 Nov 2024

    EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17488

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and accessing the print badge screen, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17487

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to gain elevated privileges on the system, caused by an error in the printer dialog. By visiting the kiosk and signing in as a visitor, an attacker could exploit this vulnerability using the command line to break out of kiosk mode.

    Published: 19 Mar 2019
    2.9
    Low

    CVE-2018-17486

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete visitor records or remove a host.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17485

    Last Modified: 21 Nov 2024

    Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

    Published: 19 Mar 2019
    4
    Medium

    CVE-2018-17484

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Sample Database.mdb database while in kiosk mode. By using attack vectors outlined in kiosk breakout, an attacker could exploit this vulnerability to view and edit the database.

    Published: 19 Mar 2019
    2.9
    Low

    CVE-2018-17483

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and viewing the driver's license column, an attacker could exploit this vulnerability to view the driver's license number and other personal information.

    Published: 19 Mar 2019
    4
    Medium

    CVE-2018-17482

    Last Modified: 21 Nov 2024

    Lobby Track Desktop could allow a local attacker to obtain sensitive information, caused by an error in Reports while in kiosk mode. By visiting the kiosk and clicking on reports, an attacker could exploit this vulnerability to gain access to all visitor records and obtain sensitive information.

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0265

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0246

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0236

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0191

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0153

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    —
    Unknown

    CVE-2018-0143

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6273

    Last Modified: 21 Nov 2024

    download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6272

    Last Modified: 21 Nov 2024

    Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

    Published: 19 Mar 2019
    7.8
    High

    CVE-2019-9878

    Last Modified: 21 Nov 2024

    There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

    Published: 19 Mar 2019
    7.8
    High

    CVE-2019-9877

    Last Modified: 21 Nov 2024

    There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example) be triggered by sending a crafted pdf file to the pdftops binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

    Published: 19 Mar 2019
    7.5
    High

    CVE-2019-5885

    Last Modified: 21 Nov 2024

    Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

    Published: 19 Mar 2019
    8.1
    High

    CVE-2019-5729

    Last Modified: 21 Nov 2024

    Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.

    Published: 19 Mar 2019
    9.8
    Critical

    CVE-2019-5723

    Last Modified: 21 Nov 2024

    An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key is static and too short. Due to this, the passwords stored by the application can be easily decrypted.

    Published: 19 Mar 2019
    9.8
    Critical

    CVE-2019-5722

    Last Modified: 21 Nov 2024

    An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.

    Published: 19 Mar 2019
    9.8
    Critical

    CVE-2019-9870

    Last Modified: 21 Nov 2024

    plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements.

    Published: 19 Mar 2019
    7.2
    High

    CVE-2019-9868

    Last Modified: 21 Nov 2024

    An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.

    Published: 19 Mar 2019
    7.2
    High

    CVE-2019-9867

    Last Modified: 21 Nov 2024

    An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is displayed to an administrator.

    Published: 19 Mar 2019
    7.8
    High

    CVE-2019-4094

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege user full access to root by loading a malicious shared library. IBM X-Force ID: 158014.

    Published: 19 Mar 2019
    5.4
    Medium

    CVE-2018-1836

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.1.0.0, and 9.1.0.1 console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150661.

    Published: 19 Mar 2019
    7.8
    High

    CVE-2019-19543

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.1.6, there is a use-after-free in serial_ir_init_module() in drivers/media/rc/serial_ir.c.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-3874

    Last Modified: 21 Nov 2024

    The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

    Published: 19 Mar 2019
    5.5
    Medium

    CVE-2019-20811

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c.

    Published: 19 Mar 2019
    6.1
    Medium

    CVE-2016-10744

    Last Modified: 21 Nov 2024

    In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.

    Published: 19 Mar 2019
    7.5
    High

    CVE-2019-10901

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.

    Published: 19 Mar 2019
    7.5
    High

    CVE-2019-10902

    Last Modified: 21 Nov 2024

    In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting strings safely.

    Published: 19 Mar 2019
    6.1
    Medium

    CVE-2019-9094

    Last Modified: 21 Nov 2024

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing JavaScript in the filename is echoed back in JavaScript code, which resulted in XSS.

    Published: 18 Mar 2019
    6.1
    Medium

    CVE-2019-9093

    Last Modified: 21 Nov 2024

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Edition. The user-supplied input containing a JavaScript payload in the filename parameter is echoed back, which resulted in reflected XSS.

    Published: 18 Mar 2019
    5.5
    Medium

    CVE-2019-6492

    Last Modified: 21 Nov 2024

    SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC4 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-7161

    Last Modified: 30 May 2025

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-6970

    Last Modified: 30 May 2025

    Moodle 3.5.x before 3.5.4 allows SSRF.

    Published: 18 Mar 2019
    5.4
    Medium

    CVE-2018-20736

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.

    Published: 18 Mar 2019
    5.4
    Medium

    CVE-2018-20737

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. Reflected XSS exists in the carbon part of the product.

    Published: 18 Mar 2019
    7
    High

    CVE-2018-18466

    Last Modified: 30 May 2025

    An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency credentials in cleartext in the logs (present in the DEBUG folder) that can be accessed by anyone. NOTE: The vendor disputes this as a vulnerability since the disclosure of a local account password (actually an alpha numeric passcode) is achievable only when a custom registry key is added to the windows registry. This action requires administrator access and the registry key is only provided by support staff at securenvoy to troubleshoot customer issues.

    Published: 18 Mar 2019
    9.1
    Critical

    CVE-2018-19365

    Last Modified: 21 Nov 2024

    The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP request.

    Published: 18 Mar 2019
    6.1
    Medium

    CVE-2019-7299

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.

    Published: 18 Mar 2019
    5.4
    Medium

    CVE-2018-14724

    Last Modified: 21 Nov 2024

    In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.

    Published: 18 Mar 2019
    7.8
    High

    CVE-2019-6724

    Last Modified: 21 Nov 2024

    The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

    Published: 18 Mar 2019