6.1
    Medium

    CVE-2019-19393

    Last Modified: 21 Nov 2024

    The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.

    Published:1 Oct 2020
    8.8
    High

    CVE-2019-19383

    Last Modified: 21 Nov 2024

    freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).

    Published:3 Dec 2019
    Unknown

    CVE-2019-19369

    https://github.com/TheCyberGeek/CVE-2019-19369

    6.1
    Medium

    CVE-2019-19368

    Last Modified: 18 Dec 2019

    A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts

    Source:Harshit Shukla
    Published:16 Dec 2019
    7.8
    High

    CVE-2019-19363

    Last Modified: 10 Feb 2020

    An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver - All versions Generic PCL5 Driver - All versions RPCS Driver - All versions PostScript3 Driver - All versions PCL6 (PCL XL) Driver - All versions RPCS Raster Driver - All version

    Source:Metasploit
    Published:24 Jan 2020
    7.5
    High

    CVE-2019-19356

    Last Modified: 7 Nov 2025

    Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

    Published:7 Feb 2020
    7.1
    High

    CVE-2019-19315

    Last Modified: 21 Nov 2024

    NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nlsX86ccMailslot mailslot.

    Published:17 Dec 2019
    Unknown

    CVE-2019-19268

    https://github.com/TheCyberGeek/CVE-2019-19268

    9.8
    Critical

    CVE-2019-19245

    Last Modified: 14 Apr 2025

    NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.

    Source:hyp3rlinx
    Published:2 Dec 2019
    7.8
    High

    CVE-2019-19241

    Last Modified: 16 Dec 2019

    In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG operations, although requested in the context of an unprivileged user, are sometimes performed by a kernel worker thread without considering that context.

    Source:Google Security Research
    Published:25 Nov 2019
    7.3
    High

    CVE-2019-19231

    Last Modified: 21 Nov 2024

    An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.

    Published:20 Dec 2019
    9.8
    Critical

    CVE-2019-19208

    Last Modified: 24 May 2021

    Codiad Web IDE through 2.8.4 allows PHP Code injection.

    Source:Ron Jost
    Published:16 Mar 2020
    7.5
    High

    CVE-2019-19204

    Last Modified: 21 Nov 2024

    An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

    Published:6 Nov 2019
    7.5
    High

    CVE-2019-19203

    Last Modified: 21 Nov 2024

    An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.

    Published:6 Nov 2019
    8.8
    High

    CVE-2019-19194

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices installs a zero long term key (LTK) if an out-of-order link-layer encryption request is received during Secure Connections pairing. An attacker in radio range can have arbitrary read/write access to protected GATT service data, cause a device crash, or possibly control a device's function by establishing an encrypted session with the zero LTK.

    Published:12 Feb 2020
    6.1
    Medium

    CVE-2019-19143

    Last Modified: 2 Mar 2020

    TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.

    Source:Elber Tavares
    Published:27 Jan 2020
    7.5
    High

    CVE-2019-19142

    Last Modified: 2 Mar 2020

    Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.

    Source:Elber Tavares
    Published:17 Jan 2020
    9.8
    Critical

    CVE-2019-19033

    Last Modified: 21 Nov 2024

    Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.

    Published:21 Nov 2019
    8.1
    High

    CVE-2019-19032

    Last Modified: 29 Jan 2020

    XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload.

    Source:Javier Olmedo
    Published:30 Dec 2019
    8.1
    High

    CVE-2019-19031

    Last Modified: 20 Jan 2020

    Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.

    Source:Javier Olmedo
    Published:30 Dec 2019
    5.3
    Medium

    CVE-2019-19030

    Last Modified: 14 Apr 2025

    Cloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls reveal (via the HTTP status code) whether a resource exists.

    Published:26 Dec 2022
    9.8
    Critical

    CVE-2019-19012

    Last Modified: 21 Nov 2024

    An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

    Published:8 Nov 2019
    7
    High

    CVE-2019-18988

    Last Modified: 7 Nov 2025

    TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.

    Published:7 Feb 2020
    7.5
    High

    CVE-2019-18951

    Last Modified: 14 Nov 2019

    SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.

    Source:Noman Riffat
    Published:13 Nov 2019
    9.8
    Critical

    CVE-2019-18935

    Last Modified: 18 Dec 2019

    Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

    Source:Bishop Fox
    Published:11 Dec 2019
    7.8
    High

    CVE-2019-18915

    Last Modified: 12 Feb 2020

    A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Event Utility system service.

    Source:hyp3rlinx
    Published:12 Feb 2020
    6.5
    Medium

    CVE-2019-18890

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

    Published:21 Nov 2019
    5.5
    Medium

    CVE-2019-18885

    Last Modified: 21 Nov 2024

    fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices->devices is mishandled within find_device, aka CID-09ba3bc9dd15.

    Published:19 Jan 2019
    9
    Critical

    CVE-2019-18873

    Last Modified: 13 Nov 2019

    FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.

    Source:liquidsky
    Published:12 Nov 2019
    7.8
    High

    CVE-2019-18862

    Last Modified: 21 Nov 2019

    maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.

    Source:Mike Gualtieri
    Published:11 Nov 2019
    6.1
    Medium

    CVE-2019-18859

    Last Modified: 13 Jan 2020

    Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.

    Source:Raspina Net Pars Group
    Published:9 Jan 2020
    7.1
    High

    CVE-2019-18845

    Last Modified: 21 Nov 2024

    The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

    Published:9 Nov 2019
    9.8
    Critical

    CVE-2019-18818

    Last Modified: 30 Aug 2021

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

    Source:David Anglada
    Published:7 Nov 2019
    7
    High

    CVE-2019-18683

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.

    Published:4 Nov 2019
    9.8
    Critical

    CVE-2019-18655

    Last Modified: 21 Nov 2024

    File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated attacker is able to perform remote command execution and obtain a command shell by sending a HTTP GET request including the malicious payload in the URL. A similar issue to CVE-2019-17415, CVE-2019-16724, and CVE-2010-2331.

    Published:12 Nov 2019
    7.8
    High

    CVE-2019-18634

    Last Modified: 11 Feb 2020

    In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.

    Source:Joe Vennix
    Published:29 Jan 2020
    8.2
    High

    CVE-2019-18426

    Last Modified: 6 Apr 2020

    A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

    Source:Gal Weizman
    Published:21 Jan 2020
    9.8
    Critical

    CVE-2019-18418

    Last Modified: 25 Oct 2019

    clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

    Source:İbrahim Hakan Şeker
    Published:24 Oct 2019
    7.2
    High

    CVE-2019-18396

    Last Modified: 13 Nov 2019

    An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.

    Source:João Teles
    Published:31 Oct 2019
    9.8
    Critical

    CVE-2019-18394

    Last Modified: 21 Nov 2024

    A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

    Published:24 Oct 2019
    5.3
    Medium

    CVE-2019-18393

    Last Modified: 21 Nov 2024

    PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

    Published:24 Oct 2019
    7.5
    High

    CVE-2019-18371

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.

    Published:23 Oct 2019
    9.8
    Critical

    CVE-2019-18370

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.

    Published:23 Oct 2019
    7.8
    High

    CVE-2019-18276

    Last Modified: 9 Jun 2025

    An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved UID" functionality, the saved UID is not dropped. An attacker with command execution in the shell can use "enable -f" for runtime loading of a new builtin, which can be a shared object that calls setuid() and therefore regains privileges. However, binaries running with an effective UID of 0 are unaffected.

    Published:1 Jul 2019
    7.8
    High

    CVE-2019-18194

    Last Modified: 23 Apr 2020

    TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.

    Source:Kusol Watchara-Apanukorn
    Published:10 Jan 2020
    5.3
    Medium

    CVE-2019-17671

    Last Modified: 19 Nov 2019

    In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.

    Source:Sebastian Neef
    Published:17 Oct 2019
    8.8
    High

    CVE-2019-17666

    Last Modified: 21 Nov 2024

    rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.

    Published:17 Oct 2019
    9.8
    Critical

    CVE-2019-17662

    Last Modified: 12 Feb 2020

    ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

    Source:Nikhith Tumamlapalli
    Published:16 Oct 2019
    9.8
    Critical

    CVE-2019-17658

    Last Modified: 21 Nov 2024

    An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path.

    Published:12 Mar 2020
    9.8
    Critical

    CVE-2019-17640

    Last Modified: 21 Nov 2024

    In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.

    Published:15 Oct 2020