7.8
    High

    CVE-2019-20501

    Last Modified: 9 Mar 2020

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.

    Source:Raki Ben Hamouda
    Published:5 Mar 2020
    7.8
    High

    CVE-2019-20500

    Last Modified: 9 Mar 2020

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

    Source:Raki Ben Hamouda
    Published:5 Mar 2020
    7.8
    High

    CVE-2019-20499

    Last Modified: 31 Mar 2020

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter.

    Source:Metasploit
    Published:5 Mar 2020
    5.3
    Medium

    CVE-2019-20372

    Last Modified: 21 Nov 2024

    NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

    Published:9 Jan 2020
    9.8
    Critical

    CVE-2019-20361

    Last Modified: 26 Jul 2020

    There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

    Source:KBA@SOGETI_ESEC
    Published:8 Jan 2020
    4.3
    Medium

    CVE-2019-20354

    Last Modified: 13 Apr 2020

    The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

    Source:JunYeong Ko
    Published:6 Jan 2020
    9.8
    Critical

    CVE-2019-20330

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

    Published:2 Jan 2020
    7.8
    High

    CVE-2019-20326

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

    Published:19 Jan 2020
    8.8
    High

    CVE-2019-20224

    Last Modified: 21 Nov 2024

    netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

    Published:9 Jan 2020
    9.8
    Critical

    CVE-2019-20215

    Last Modified: 10 Feb 2020

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

    Source:Metasploit
    Published:29 Jan 2020
    5.4
    Medium

    CVE-2019-20204

    Last Modified: 16 Jan 2020

    The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.

    Source:V1n1v131r4
    Published:1 Jan 2020
    8.8
    High

    CVE-2019-20197

    Last Modified: 21 Nov 2024

    In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

    Published:31 Dec 2019
    7.5
    High

    CVE-2019-20149

    Last Modified: 21 Nov 2024

    ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

    Published:16 Dec 2019
    7.5
    High

    CVE-2019-20085

    Last Modified: 13 Apr 2020

    TVT NVMS-1000 devices allow GET /.. Directory Traversal

    Source:Mohin Paramasivam
    Published:30 Dec 2019
    8.8
    High

    CVE-2019-20059

    Last Modified: 21 Nov 2024

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.

    Published:10 Feb 2020
    5.3
    Medium

    CVE-2019-19985

    Last Modified: 26 Jul 2020

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

    Source:KBA@SOGETI_ESEC
    Published:26 Dec 2019
    7.5
    High

    CVE-2019-19945

    Last Modified: 21 Nov 2024

    uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.

    Published:16 Mar 2020
    9.8
    Critical

    CVE-2019-19919

    Last Modified: 21 Nov 2024

    Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

    Published:24 Sept 2019
    9.8
    Critical

    CVE-2019-19905

    Last Modified: 21 Nov 2024

    NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.

    Published:19 Dec 2019
    Unknown

    CVE-2019-19871

    https://github.com/VDISEC/CVE-2019-19871-AuditGuide

    9.8
    Critical

    CVE-2019-19844

    Last Modified: 13 Apr 2020

    Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

    Source:Ryuji Tsutsui
    Published:18 Dec 2019
    9.8
    Critical

    CVE-2019-19842

    Last Modified: 21 Nov 2024

    emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.

    Published:22 Jan 2020
    9.8
    Critical

    CVE-2019-19782

    Last Modified: 21 Nov 2024

    The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.

    Published:13 Dec 2019
    9.8
    Critical

    CVE-2019-19781

    Last Modified: 16 Jan 2020

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

    Source:Dhiraj Mishra
    Published:27 Dec 2019
    8.8
    High

    CVE-2019-19774

    Last Modified: 24 Feb 2020

    An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.

    Source:Scott Goodwin
    Published:13 Dec 2019
    6.5
    Medium

    CVE-2019-19743

    Last Modified: 17 Dec 2019

    On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

    Source:Sanyam Chawla
    Published:16 Dec 2019
    4.8
    Medium

    CVE-2019-19742

    Last Modified: 20 Dec 2019

    On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.

    Source:Sanyam Chawla
    Published:18 Dec 2019
    9.8
    Critical

    CVE-2019-19740

    Last Modified: 28 Jan 2020

    Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.

    Source:Bruno de Barros Bulle
    Published:12 Dec 2019
    7.5
    High

    CVE-2019-19731

    Last Modified: 18 Dec 2019

    Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

    Source:Patrik Lantz
    Published:16 Dec 2019
    7.8
    High

    CVE-2019-19726

    Last Modified: 30 Dec 2019

    OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from the environment, but fails when it cannot allocate memory. Thus, the attacker is able to execute their own library code as root.

    Source:Metasploit
    Published:12 Dec 2019
    7.2
    High

    CVE-2019-19699

    Last Modified: 21 Nov 2024

    There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To exploit the vulnerability, someone must have Admin access to the Centreon Web Interface and create a custom main.php?p=60803&type=3 command. The user must then set the Pollers Post-Restart Command to this previously created command via the main.php?p=60901&o=c&server_id=1 URI. This is triggered via an export of the Poller Configuration.

    Published:6 Apr 2020
    Unknown

    CVE-2019-19658

    https://github.com/jra89/CVE-2019-19658

    Unknown

    CVE-2019-19654

    https://github.com/jra89/CVE-2019-19654

    Unknown

    CVE-2019-19653

    https://github.com/jra89/CVE-2019-19653

    Unknown

    CVE-2019-19652

    https://github.com/jra89/CVE-2019-19652

    Unknown

    CVE-2019-19651

    https://github.com/jra89/CVE-2019-19651

    9.8
    Critical

    CVE-2019-19634

    Last Modified: 21 Nov 2024

    class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

    Published:17 Dec 2019
    Unknown

    CVE-2019-19633

    https://github.com/jra89/CVE-2019-19633

    7.2
    High

    CVE-2019-19609

    Last Modified: 30 Aug 2021

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.

    Source:David Utón
    Published:5 Dec 2019
    9.8
    Critical

    CVE-2019-19576

    Last Modified: 6 Dec 2019

    class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

    Source:Jinny Ramsmark
    Published:4 Dec 2019
    7.5
    High

    CVE-2019-19550

    Last Modified: 21 Nov 2024

    Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.

    Published:31 Jan 2020
    6.1
    Medium

    CVE-2019-19547

    Last Modified: 21 Nov 2024

    Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.

    Published:13 Jan 2020
    7.8
    High

    CVE-2019-19520

    Last Modified: 21 Nov 2024

    xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.

    Published:4 Dec 2019
    6.5
    Medium

    CVE-2019-19516

    Last Modified: 3 Dec 2019

    Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.

    Source:Prof. Joas Antonio
    Published:2 Dec 2019
    Unknown

    CVE-2019-19511

    https://github.com/jra89/CVE-2019-19511

    8.8
    High

    CVE-2019-19509

    Last Modified: 17 Mar 2020

    An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.

    Source:Metasploit
    Published:6 Jan 2020
    5.4
    Medium

    CVE-2019-19493

    Last Modified: 9 Oct 2020

    Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.

    Source:Ataberk YAVUZER
    Published:2 Dec 2019
    9.8
    Critical

    CVE-2019-19492

    Last Modified: 21 Nov 2024

    FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

    Published:2 Dec 2019
    7.8
    High

    CVE-2019-19470

    Last Modified: 21 Nov 2024

    Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.

    Published:30 Dec 2019
    7.8
    High

    CVE-2019-19447

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.

    Published:8 Dec 2019