CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-11790

    Last Modified: 21 Nov 2024

    When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.

    Published: 31 Jan 2019
    6.1
    Medium

    CVE-2019-4040

    Last Modified: 21 Nov 2024

    IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 156164.

    Published: 31 Jan 2019
    6.1
    Medium

    CVE-2019-7250

    Last Modified: 21 Nov 2024

    An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references text to inject arbitrary JavaScript code (via SCRIPT elements, event handlers, etc.). Since this code is stored by the plugin, the attacker may be able to target anyone who opens the configuration panel of the plugin.

    Published: 31 Jan 2019
    7.8
    High

    CVE-2019-7216

    Last Modified: 21 Nov 2024

    An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user to upload any type of file by using % characters within the extension, e.g., file.%ph%p becomes file.php.

    Published: 31 Jan 2019
    9.8
    Critical

    CVE-2019-6438

    Last Modified: 21 Nov 2024

    SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.

    Published: 31 Jan 2019
    9.8
    Critical

    CVE-2019-7249

    Last Modified: 21 Nov 2024

    In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.

    Published: 31 Jan 2019
    6.1
    Medium

    CVE-2019-3826

    Last Modified: 21 Nov 2024

    A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.

    Published: 31 Jan 2019
    7.4
    High

    CVE-2019-7283

    Last Modified: 21 Nov 2024

    An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.

    Published: 31 Jan 2019
    7.1
    High

    CVE-2018-3956

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory content and aid in exploitation when coupled with another vulnerability. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 30 Jan 2019
    7.5
    High

    CVE-2019-7236

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.

    Published: 30 Jan 2019
    7.5
    High

    CVE-2019-7235

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?app=apps&do=uninstall request.

    Published: 30 Jan 2019
    8.8
    High

    CVE-2019-7233

    Last Modified: 21 Nov 2024

    In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.

    Published: 30 Jan 2019
    9.1
    Critical

    CVE-2019-7234

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can then be downloaded via an admincp.php?app=apps&do=pack request.

    Published: 30 Jan 2019
    7.5
    High

    CVE-2019-7237

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=browse ..\ Directory Traversal.

    Published: 30 Jan 2019
    5.4
    Medium

    CVE-2019-1565

    Last Modified: 21 Nov 2024

    The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that is authenticated in Next Generation Firewall with write privileges to External Dynamic List configuration to inject arbitrary JavaScript or HTML.

    Published: 30 Jan 2019
    6.1
    Medium

    CVE-2019-1566

    Last Modified: 21 Nov 2024

    The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.

    Published: 30 Jan 2019
    6.1
    Medium

    CVE-2019-3911

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an unauthenticated remote attacker to inject arbitrary javascript via the onerror parameter in the /__r2/query endpoints.

    Published: 30 Jan 2019
    6.1
    Medium

    CVE-2019-3912

    Last Modified: 21 Nov 2024

    An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

    Published: 30 Jan 2019
    4.9
    Medium

    CVE-2019-3913

    Last Modified: 21 Nov 2024

    Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker to unmount any drive on the system leading to denial of service.

    Published: 30 Jan 2019
    7.8
    High

    CVE-2018-19027

    Last Modified: 21 Nov 2024

    Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.

    Published: 30 Jan 2019
    —
    Unknown

    CVE-2018-18895

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3004. Reason: This candidate is a duplicate of CVE-2014-3004. Notes: All CVE users should reference CVE-2014-3004 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Jan 2019
    5.3
    Medium

    CVE-2018-19440

    Last Modified: 5 Jun 2026

    ARM Trusted Firmware-A allows information disclosure.

    Published: 29 Jan 2019
    5.3
    Medium

    CVE-2018-12610

    Last Modified: 21 Nov 2024

    OX App Suite 7.8.4 and earlier allows Information Exposure.

    Published: 29 Jan 2019
    6.1
    Medium

    CVE-2018-12611

    Last Modified: 21 Nov 2024

    OX App Suite 7.8.4 and earlier allows Directory Traversal.

    Published: 29 Jan 2019
    6.1
    Medium

    CVE-2018-19782

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

    Published: 29 Jan 2019
    8.6
    High

    CVE-2018-19858

    Last Modified: 21 Nov 2024

    PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2018-12609

    Last Modified: 21 Nov 2024

    OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.

    Published: 29 Jan 2019
    5.3
    Medium

    CVE-2018-15136

    Last Modified: 21 Nov 2024

    TitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send malicious emails to an entire organization by modifying the URL requests sent to the application.

    Published: 29 Jan 2019
    9.8
    Critical

    CVE-2018-17431

    Last Modified: 21 Nov 2024

    Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.

    Published: 29 Jan 2019
    4.8
    Medium

    CVE-2019-7168

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Blog field to /admin/nodes/nodes/add/blog.

    Published: 29 Jan 2019
    4.8
    Medium

    CVE-2019-7169

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/menus/menus/edit/3.

    Published: 29 Jan 2019
    4.8
    Medium

    CVE-2019-7170

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/taxonomy/vocabularies.

    Published: 29 Jan 2019
    4.8
    Medium

    CVE-2019-7171

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/blocks/blocks/edit/8.

    Published: 29 Jan 2019
    6.1
    Medium

    CVE-2019-7172

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Real Name field to /mods/_core/users/admins/my_edit.php.

    Published: 29 Jan 2019
    4.8
    Medium

    CVE-2019-7173

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/file-manager/attachments/edit/4.

    Published: 29 Jan 2019
    8.1
    High

    CVE-2019-3806

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

    Published: 29 Jan 2019
    3.7
    Low

    CVE-2019-3807

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.

    Published: 29 Jan 2019
    5.3
    Medium

    CVE-2018-1668

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 7.5.0.0 through 7.5.0.19, 7.5.1.0 through 7.5.1.18, 7.5.2.0 through 7.5.2.18, and 7.6.0.0 through 7.6.0.11 appliances allows "null" logins which could give read access to IPMI data to obtain sensitive information. IBM X-Force ID: 144894.

    Published: 29 Jan 2019
    5.4
    Medium

    CVE-2018-18985

    Last Modified: 21 Nov 2024

    Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all versions prior to 4.6.96.28.4 a cross-site scripting vulnerability has been identified that may allow a remote attacker to inject code to some web pages affecting confidentiality.

    Published: 29 Jan 2019
    5.3
    Medium

    CVE-2018-1733

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 fails to adequately filter user-controlled input data for syntax that has control-plane implications which could allow an attacker to modify displayed content. IBM X-Force ID: 147811.

    Published: 29 Jan 2019
    9.8
    Critical

    CVE-2019-7160

    Last Modified: 21 Nov 2024

    idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.

    Published: 29 Jan 2019
    9.8
    Critical

    CVE-2018-10612

    Last Modified: 21 Nov 2024

    In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.

    Published: 29 Jan 2019
    4.9
    Medium

    CVE-2018-1976

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.4 is impacted by sensitive information disclosure via a REST API that could allow a user with administrative privileges to obtain highly sensitive information. IBM X-Force ID: 154031.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-7156

    Last Modified: 21 Nov 2024

    In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero.

    Published: 29 Jan 2019
    4.9
    Medium

    CVE-2016-10740

    Last Modified: 21 Nov 2024

    Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.

    Published: 29 Jan 2019
    10
    Critical

    CVE-2018-18505

    Last Modified: 25 Nov 2025

    An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5757

    Last Modified: 21 Nov 2024

    An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5763

    Last Modified: 21 Nov 2024

    Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5769

    Last Modified: 21 Nov 2024

    Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5772

    Last Modified: 21 Nov 2024

    Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 29 Jan 2019