CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-20140

    Last Modified: 21 Nov 2024

    Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7421

    Last Modified: 21 Nov 2024

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple parameters: contextpath and basedURL.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7420

    Last Modified: 21 Nov 2024

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-20121

    Last Modified: 21 Nov 2024

    Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7419

    Last Modified: 21 Nov 2024

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-18845

    Last Modified: 21 Nov 2024

    internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7418

    Last Modified: 21 Nov 2024

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc.

    Published: 17 Mar 2019
    8.1
    High

    CVE-2019-5414

    Last Modified: 21 Nov 2024

    If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7417

    Last Modified: 21 Nov 2024

    XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7416

    Last Modified: 21 Nov 2024

    XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable.

    Published: 17 Mar 2019
    4.8
    Medium

    CVE-2018-19934

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2019-5416

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-18798

    Last Modified: 21 Nov 2024

    Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2019-7391

    Last Modified: 21 Nov 2024

    ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2019-5415

    Last Modified: 21 Nov 2024

    A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2019-5417

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.

    Published: 17 Mar 2019
    6.5
    Medium

    CVE-2019-7386

    Last Modified: 5 Jun 2026

    A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-19917

    Last Modified: 21 Nov 2024

    Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.

    Published: 17 Mar 2019
    6.5
    Medium

    CVE-2018-18762

    Last Modified: 21 Nov 2024

    SaltOS 3.1 r8126 contains a database download vulnerability.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-11747

    Last Modified: 21 Nov 2024

    Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificate for ingress.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-6517

    Last Modified: 21 Nov 2024

    Prior to version 0.3.0, chloride's use of net-ssh resulted in host fingerprints for previously unknown hosts getting added to the user's known_hosts file without confirmation. In version 0.3.0 this is updated so that the user's known_hosts file is not updated by chloride.

    Published: 17 Mar 2019
    7.8
    High

    CVE-2019-7385

    Last Modified: 21 Nov 2024

    An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and confpass parameters in /bin/WebMGR are used in a system call in the firmware. Because there is no user input validation, this leads to authenticated code execution on the device.

    Published: 17 Mar 2019
    7.8
    High

    CVE-2018-18435

    Last Modified: 21 Nov 2024

    KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders. In addition, the program installs a service called "KWSService" which runs as "Localsystem", this will allow any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a malicious one.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19783

    Last Modified: 21 Nov 2024

    Kentix MultiSensor-LAN 5.63.00 devices and previous allow Authentication Bypass via an Alternate Path or Channel.

    Published: 17 Mar 2019
    7.8
    High

    CVE-2019-7384

    Last Modified: 21 Nov 2024

    An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below. The value of the fmgpon_loid parameter is used in a system call inside the boa binary. Because there is no user input validation, this leads to authenticated code execution on the device.

    Published: 17 Mar 2019
    7.8
    High

    CVE-2019-7383

    Last Modified: 21 Nov 2024

    An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command injection via the des parameter.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-17997

    Last Modified: 21 Nov 2024

    LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).

    Published: 17 Mar 2019
    5.4
    Medium

    CVE-2018-13104

    Last Modified: 21 Nov 2024

    OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-19694

    Last Modified: 21 Nov 2024

    HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

    Published: 17 Mar 2019
    6.5
    Medium

    CVE-2018-17996

    Last Modified: 21 Nov 2024

    LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

    Published: 17 Mar 2019
    5.4
    Medium

    CVE-2018-13103

    Last Modified: 21 Nov 2024

    OX App Suite 7.8.4 and earlier allows SSRF.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-19525

    Last Modified: 21 Nov 2024

    An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19524

    Last Modified: 21 Nov 2024

    An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-8938

    Last Modified: 21 Nov 2024

    VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-16789

    Last Modified: 21 Nov 2024

    libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19515

    Last Modified: 21 Nov 2024

    In Webgalamb through 7.0, system/ajax.php functionality is supposed to be available only to the administrator. However, by using one of the bgsend, atment_sddd1xGz, or xls_bgimport query parameters, most of these methods become available to unauthenticated users.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-12638

    Last Modified: 21 Nov 2024

    An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.

    Published: 17 Mar 2019
    7.8
    High

    CVE-2018-12572

    Last Modified: 21 Nov 2024

    Avast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive information by dumping AvastUI.exe application memory and parsing the data.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2019-6973

    Last Modified: 21 Nov 2024

    Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2019-6967

    Last Modified: 21 Nov 2024

    AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.

    Published: 17 Mar 2019
    9.4
    Critical

    CVE-2019-6716

    Last Modified: 21 Nov 2024

    An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2019-6714

    Last Modified: 21 Nov 2024

    An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.

    Published: 17 Mar 2019
    5.9
    Medium

    CVE-2019-6702

    Last Modified: 21 Nov 2024

    The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obsolete versions from 2016 or earlier.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2019-9083

    Last Modified: 21 Nov 2024

    SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is discontinued.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2018-10093

    Last Modified: 21 Nov 2024

    AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

    Published: 17 Mar 2019
    4.8
    Medium

    CVE-2018-10091

    Last Modified: 21 Nov 2024

    AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.

    Published: 17 Mar 2019
    5.4
    Medium

    CVE-2019-7223

    Last Modified: 21 Nov 2024

    InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.

    Published: 16 Mar 2019
    8.8
    High

    CVE-2019-9846

    Last Modified: 21 Nov 2024

    RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.

    Published: 16 Mar 2019
    6.1
    Medium

    CVE-2018-20807

    Last Modified: 21 Nov 2024

    An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.

    Published: 16 Mar 2019
    6.1
    Medium

    CVE-2018-20808

    Last Modified: 21 Nov 2024

    An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.

    Published: 16 Mar 2019