CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2019-6521

    Last Modified: 21 Nov 2024

    WebAccess/SCADA, Version 8.3. Specially crafted requests could allow a possible authentication bypass that could allow an attacker to obtain and manipulate sensitive information.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2019-6523

    Last Modified: 21 Nov 2024

    WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-18504

    Last Modified: 21 Nov 2024

    A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-18502

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.

    Published: 5 Feb 2019
    5.9
    Medium

    CVE-2018-18506

    Last Modified: 21 Nov 2024

    When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

    Published: 5 Feb 2019
    5.5
    Medium

    CVE-2018-20251

    Last Modified: 21 Nov 2024

    In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNACEV2.dll) creates files and folders as written in the filename field even when WinRAR validator noticed the traversal attempt and requestd to abort the extraction process. the operation is cancelled only after the folders and files were created but prior to them being written, therefore allowing the attacker to create empty files and folders everywhere in the file system.

    Published: 5 Feb 2019
    7.8
    High

    CVE-2018-20250

    Last Modified: 31 Oct 2025

    In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

    Published: 5 Feb 2019
    7.8
    High

    CVE-2018-20252

    Last Modified: 21 Nov 2024

    In WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 5 Feb 2019
    5.9
    Medium

    CVE-2019-6590

    Last Modified: 21 Nov 2024

    On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSL Session ID Persistence traffic.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2019-6535

    Last Modified: 26 Jun 2025

    Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.

    Published: 5 Feb 2019
    5.4
    Medium

    CVE-2019-6591

    Last Modified: 21 Nov 2024

    On BIG-IP APM 14.0.0 to 14.0.0.4, 13.0.0 to 13.1.1.3 and 12.1.0 to 12.1.3.7, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG-IP APM system.

    Published: 5 Feb 2019
    7.8
    High

    CVE-2018-18986

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code execution.

    Published: 5 Feb 2019
    8.8
    High

    CVE-2018-18992

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.

    Published: 5 Feb 2019
    5.3
    Medium

    CVE-2018-19000

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.

    Published: 5 Feb 2019
    7.8
    High

    CVE-2018-19002

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.

    Published: 5 Feb 2019
    7.8
    High

    CVE-2018-19029

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.

    Published: 5 Feb 2019
    6.1
    Medium

    CVE-2019-7413

    Last Modified: 21 Nov 2024

    In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within the PHP filename.)

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2019-7412

    Last Modified: 21 Nov 2024

    The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.

    Published: 5 Feb 2019
    5.3
    Medium

    CVE-2018-18990

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-18996

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-4056

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN server administrator web portal. An attacker can log in via the external interface of the TURN server to trigger this vulnerability.

    Published: 5 Feb 2019
    5.3
    Medium

    CVE-2017-1177

    Last Modified: 21 Nov 2024

    IBM BigFix Compliance 1.7 through 1.9.91 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 123429.

    Published: 5 Feb 2019
    3.7
    Low

    CVE-2017-1198

    Last Modified: 21 Nov 2024

    IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.

    Published: 5 Feb 2019
    3.7
    Low

    CVE-2017-1200

    Last Modified: 21 Nov 2024

    IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.

    Published: 5 Feb 2019
    5.4
    Medium

    CVE-2017-1202

    Last Modified: 21 Nov 2024

    IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 123677.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-18998

    Last Modified: 21 Nov 2024

    LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2016-1000282

    Last Modified: 21 Nov 2024

    Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.

    Published: 5 Feb 2019
    4.9
    Medium

    CVE-2019-7403

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an admin/database_backup.php?action=import&dopost=deldir&tbname=../ URI.

    Published: 5 Feb 2019
    6.1
    Medium

    CVE-2019-7402

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg&#95;qqcode parameter. This can be exploited via CSRF.

    Published: 5 Feb 2019
    4.3
    Medium

    CVE-2019-3820

    Last Modified: 21 Nov 2024

    It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2018-20753

    Last Modified: 7 Nov 2025

    Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2017-18362

    Last Modified: 5 Nov 2025

    ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

    Published: 5 Feb 2019
    6.1
    Medium

    CVE-2019-7400

    Last Modified: 21 Nov 2024

    Rukovoditel before 2.4.1 allows XSS.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2018-15656

    Last Modified: 21 Nov 2024

    An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email, where :email is a base64 encoded e-mail address, to receive confirmation as to whether a user account exists in the system with the specified e-mail address. The request must be made with an "apiKey" value in the "ApiKey" header.

    Published: 5 Feb 2019
    6.5
    Medium

    CVE-2018-15659

    Last Modified: 21 Nov 2024

    An issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin access is possible.

    Published: 5 Feb 2019
    7.3
    High

    CVE-2018-15657

    Last Modified: 21 Nov 2024

    An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2018-15658

    Last Modified: 21 Nov 2024

    An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user. This is caused by the session validation occurring after the initial markup is loaded. This results in a list of unprotected API endpoints that disclose call logs, SMS logs, and user-account data.

    Published: 5 Feb 2019
    6.5
    Medium

    CVE-2018-15655

    Last Modified: 21 Nov 2024

    An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.

    Published: 5 Feb 2019
    8.6
    High

    CVE-2019-7390

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2019-7389

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication via the SetFactoryDefault HNAP API. Consequently, an attacker can achieve a denial-of-service attack without authentication.

    Published: 5 Feb 2019
    8.8
    High

    CVE-2019-7576

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).

    Published: 5 Feb 2019
    7.7
    High

    CVE-2019-3814

    Last Modified: 21 Nov 2024

    It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this issue to impersonate other users.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2019-7388

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.

    Published: 5 Feb 2019
    6.5
    Medium

    CVE-2019-11470

    Last Modified: 21 Nov 2024

    The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.

    Published: 5 Feb 2019
    6.5
    Medium

    CVE-2019-7387

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from system/maintenance/export.php, it accepts the path provided by the user, leading to path traversal via the name parameter.

    Published: 4 Feb 2019
    —
    Unknown

    CVE-2016-1000276

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000010. Reason: This candidate is a duplicate of CVE-2017-1000010. Notes: All CVE users should reference CVE-2017-1000010 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Feb 2019
    8.8
    High

    CVE-2018-15778

    Last Modified: 21 Nov 2024

    Dell OS10 versions prior to 10.4.2.1 contain a vulnerability caused by lack of proper input validation on the command-line interface (CLI).

    Published: 4 Feb 2019
    9.8
    Critical

    CVE-2019-1000001

    Last Modified: 21 Nov 2024

    TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.

    Published: 4 Feb 2019
    6.1
    Medium

    CVE-2019-1000015

    Last Modified: 21 Nov 2024

    Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.

    Published: 4 Feb 2019
    6.5
    Medium

    CVE-2019-1000016

    Last Modified: 21 Nov 2024

    FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can result in Denial of service. This attack appears to be exploitable via specially crafted AV1 file has to be provided as input. This vulnerability appears to have been fixed in after commit b97a4b658814b2de8b9f2a3bce491c002d34de31.

    Published: 4 Feb 2019