CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-20235

    Last Modified: 21 Nov 2024

    There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.

    Published: 8 Mar 2019
    8.8
    High

    CVE-2018-20236

    Last Modified: 21 Nov 2024

    There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.

    Published: 8 Mar 2019
    7.8
    High

    CVE-2019-1601

    Last Modified: 21 Nov 2024

    A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file. The vulnerability is due to a failure to impose strict filesystem permissions on the targeted device. An attacker could exploit this vulnerability by accessing and modifying restricted files. A successful exploit could allow an attacker to use the content of this configuration file to bypass authentication and log in as any user of the device. MDS 9000 Series Multilayer Switches are affected in versions prior to 6.2(25), 8.1(1b), and 8.3(1). Nexus 3000 Series Switches are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 3500 Platform Switches are affected in versions prior to 6.0(2)A8(10) and 7.0(3)I7(4). Nexus 3600 Platform Switches are affected in versions prior to 7.0(3)F3(5). Nexus 2000, 5500, 5600, and 6000 Series Switches are affected in versions prior to 7.1(5)N1(1b) and 7.3(3)N1(1). Nexus 7000 and 7700 Series Switches are affected in versions prior to 6.2(22), 7.3(3)D1(1), and 8.2(3). Nexus 9000 Series Switches-Standalone are affected in versions prior to 7.0(3)I4(9) and 7.0(3)I7(4). Nexus 9500 R-Series Line Cards and Fabric Modules are affected in versions prior to 7.0(3)F3(5).

    Published: 8 Mar 2019
    8.8
    High

    CVE-2018-20234

    Last Modified: 21 Nov 2024

    There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.

    Published: 8 Mar 2019
    8.8
    High

    CVE-2019-3780

    Last Modified: 21 Nov 2024

    Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account.

    Published: 8 Mar 2019
    8.8
    High

    CVE-2019-3779

    Last Modified: 21 Nov 2024

    Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate leveraging the Kubernetes CSR capability to obtain a credential that could escalate privilege access to ETCD.

    Published: 8 Mar 2019
    7.8
    High

    CVE-2019-9634

    Last Modified: 21 Nov 2024

    Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.

    Published: 8 Mar 2019
    7.5
    High

    CVE-2019-9632

    Last Modified: 21 Nov 2024

    ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

    Published: 8 Mar 2019
    5.5
    Medium

    CVE-2019-9706

    Last Modified: 21 Nov 2024

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.

    Published: 8 Mar 2019
    6.5
    Medium

    CVE-2019-20395

    Last Modified: 21 Nov 2024

    A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

    Published: 8 Mar 2019
    5.5
    Medium

    CVE-2019-9704

    Last Modified: 21 Nov 2024

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

    Published: 8 Mar 2019
    5.5
    Medium

    CVE-2019-9705

    Last Modified: 21 Nov 2024

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.

    Published: 8 Mar 2019
    6.5
    Medium

    CVE-2018-18809

    Last Modified: 7 Nov 2025

    The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-14499

    Last Modified: 21 Nov 2024

    An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-16804

    Last Modified: 21 Nov 2024

    An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-16808

    Last Modified: 21 Nov 2024

    An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2018-16809

    Last Modified: 21 Nov 2024

    An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.

    Published: 7 Mar 2019
    7.5
    High

    CVE-2018-17419

    Last Modified: 21 Nov 2024

    An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2018-17412

    Last Modified: 21 Nov 2024

    zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.

    Published: 7 Mar 2019
    7.2
    High

    CVE-2018-17416

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.

    Published: 7 Mar 2019
    7.2
    High

    CVE-2018-17418

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

    Published: 7 Mar 2019
    7.2
    High

    CVE-2018-17420

    Last Modified: 21 Nov 2024

    An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-17421

    Last Modified: 21 Nov 2024

    An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-17422

    Last Modified: 21 Nov 2024

    dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

    Published: 7 Mar 2019
    5.4
    Medium

    CVE-2018-17425

    Last Modified: 5 May 2025

    WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.

    Published: 7 Mar 2019
    5.4
    Medium

    CVE-2018-17426

    Last Modified: 5 May 2025

    WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2018-17988

    Last Modified: 21 Nov 2024

    LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2019-9117

    Last Modified: 21 Nov 2024

    An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNetworkTomographySettings API function, as demonstrated by shell metacharacters in the tomography_ping_number field.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2019-9119

    Last Modified: 21 Nov 2024

    An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetStaticRouteSettings API function, as demonstrated by shell metacharacters in the staticroute_list field.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2019-7661

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.

    Published: 7 Mar 2019
    7.7
    High

    CVE-2019-8986

    Last Modified: 21 Nov 2024

    The SOAP API component vulnerability of TIBCO Software Inc.'s TIBCO JasperReports Server, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that may allow a malicious authenticated user to copy text files from the host operating system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2019-9118

    Last Modified: 21 Nov 2024

    An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetNTPServerSettings API function, as demonstrated by shell metacharacters in the system_time_timezone field.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2013-7466

    Last Modified: 21 Nov 2024

    Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2013-7467

    Last Modified: 21 Nov 2024

    Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.

    Published: 7 Mar 2019
    8.1
    High

    CVE-2013-7468

    Last Modified: 21 Nov 2024

    Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2019-6710

    Last Modified: 21 Nov 2024

    Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2019-7660

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2019-8437

    Last Modified: 21 Nov 2024

    njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.

    Published: 7 Mar 2019
    4.8
    Medium

    CVE-2019-8438

    Last Modified: 21 Nov 2024

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name.

    Published: 7 Mar 2019
    5.4
    Medium

    CVE-2019-8439

    Last Modified: 21 Nov 2024

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the second textbox of "System setting->site setting" of admin/index.php, aka site_domain.

    Published: 7 Mar 2019
    4.8
    Medium

    CVE-2019-8440

    Last Modified: 21 Nov 2024

    An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the third textbox (aka site logo) of "System setting->site setting" of admin/index.php, aka site_logo.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2019-9120

    Last Modified: 21 Nov 2024

    An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetWLanACLSettings API function, as demonstrated by shell metacharacters in the wl(0).(0)_maclist field.

    Published: 7 Mar 2019
    9.8
    Critical

    CVE-2019-9121

    Last Modified: 21 Nov 2024

    An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when any HNAP API function triggers a call to the system function with untrusted input from the request body for the SetSmartQoSSettings API function, as demonstrated by shell metacharacters in the smartqos_priority_devices field.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2019-9185

    Last Modified: 21 Nov 2024

    Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.

    Published: 7 Mar 2019
    6.5
    Medium

    CVE-2019-9598

    Last Modified: 21 Nov 2024

    An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.

    Published: 7 Mar 2019
    6.1
    Medium

    CVE-2018-17413

    Last Modified: 21 Nov 2024

    XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2018-17415

    Last Modified: 21 Nov 2024

    zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2018-17429

    Last Modified: 21 Nov 2024

    /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.

    Published: 7 Mar 2019
    10
    Critical

    CVE-2018-18815

    Last Modified: 21 Nov 2024

    The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability that theoretically allows unauthenticated users to bypass authorization checks for portions of the HTTP interface to the JasperReports Server. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.

    Published: 7 Mar 2019
    8.8
    High

    CVE-2018-17414

    Last Modified: 21 Nov 2024

    zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.

    Published: 7 Mar 2019