7.5
    High

    CVE-2019-16758

    Last Modified: 25 Nov 2019

    In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.

    Source:Kevin Randall
    Published:21 Nov 2019
    9.8
    Critical

    CVE-2019-16746

    Last Modified: 21 Nov 2024

    An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.

    Published:11 Sept 2019
    9.8
    Critical

    CVE-2019-16724

    Last Modified: 24 Sept 2019

    File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.

    Source:x00pwn
    Published:24 Sept 2019
    9.8
    Critical

    CVE-2019-16702

    Last Modified: 6 Dec 2019

    Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin URI.

    Source:purpl3f0xsecur1ty
    Published:23 Sept 2019
    8.8
    High

    CVE-2019-16701

    Last Modified: 18 Jun 2020

    pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

    Source:Nassim Asrir
    Published:25 Sept 2019
    9.8
    Critical

    CVE-2019-16693

    Last Modified: 3 Dec 2025

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

    Source:CodeSecLab
    Published:22 Sept 2019
    9.8
    Critical

    CVE-2019-16692

    Last Modified: 30 Sept 2019

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.

    Source:Kevin Kirsche
    Published:22 Sept 2019
    4.9
    Medium

    CVE-2019-16679

    Last Modified: 23 Sept 2019

    Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.

    Source:Sainadh Jamalpur
    Published:21 Sept 2019
    8.8
    High

    CVE-2019-16667

    Last Modified: 26 Jul 2020

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.

    Source:ghost_fh
    Published:26 Sept 2019
    8.8
    High

    CVE-2019-16663

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to command execution.

    Published:28 Oct 2019
    9.8
    Critical

    CVE-2019-16662

    Last Modified: 8 Nov 2019

    An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

    Source:Metasploit
    Published:28 Oct 2019
    8.6
    High

    CVE-2019-16645

    Last Modified: 30 Sept 2019

    An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

    Source:Ramikan
    Published:20 Sept 2019
    8.8
    High

    CVE-2019-16531

    Last Modified: 20 Sept 2019

    LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

    Source:0xB9
    Published:20 Sept 2019
    5.3
    Medium

    CVE-2019-16516

    Last Modified: 5 Jan 2022

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration vulnerability, allowing an unauthenticated attacker to determine with certainty if an account exists for a given username.

    Source:Luca Cuzzolin
    Published:23 Jan 2020
    9.8
    Critical

    CVE-2019-16451

    Last Modified: 11 Dec 2019

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:19 Dec 2019
    7.2
    High

    CVE-2019-16405

    Last Modified: 28 Jan 2020

    Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.

    Source:TheCyberGeek
    Published:21 Nov 2019
    9.8
    Critical

    CVE-2019-16399

    Last Modified: 19 Sept 2019

    Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH from /admin/system_advanced.php?lang=en and login with the default root password welc0me.

    Source:Noman Riffat
    Published:18 Sept 2019
    5.3
    Medium

    CVE-2019-16394

    Last Modified: 21 Nov 2024

    SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

    Published:17 Sept 2019
    9.4
    Critical

    CVE-2019-16383

    Last Modified: 23 Nov 2020

    MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.

    Source:Aviv Beniash
    Published:24 Sept 2019
    9.8
    Critical

    CVE-2019-16374

    Last Modified: 21 Nov 2024

    Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

    Published:13 Aug 2020
    9.8
    Critical

    CVE-2019-16335

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

    Published:15 Sept 2019
    7.8
    High

    CVE-2019-16294

    Last Modified: 18 Jun 2020

    SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.

    Source:Bogdan Kurinnoy
    Published:14 Sept 2019
    7.5
    High

    CVE-2019-16279

    Last Modified: 21 Nov 2024

    A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.

    Published:14 Oct 2019
    9.8
    Critical

    CVE-2019-16278

    Last Modified: 1 Nov 2019

    Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.

    Source:Metasploit
    Published:14 Oct 2019
    7.8
    High

    CVE-2019-16253

    Last Modified: 21 Nov 2024

    The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate privileges, e.g., to system privileges. The Samsung case ID is 101755.

    Published:25 Sept 2019
    5.4
    Medium

    CVE-2019-16223

    Last Modified: 4 Jan 2021

    WordPress before 5.2.3 allows XSS in post previews by authenticated users.

    Source:gx1
    Published:11 Sept 2019
    6.1
    Medium

    CVE-2019-16197

    Last Modified: 13 Sept 2019

    In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

    Source:Metin Yunus Kandemir
    Published:16 Sept 2019
    5.4
    Medium

    CVE-2019-16173

    Last Modified: 13 Sept 2019

    LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,

    Source:SEC Consult
    Published:9 Sept 2019
    5.4
    Medium

    CVE-2019-16172

    Last Modified: 13 Sept 2019

    LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

    Source:SEC Consult
    Published:9 Sept 2019
    9.8
    Critical

    CVE-2019-16119

    Last Modified: 10 Sept 2019

    SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

    Source:MTK
    Published:8 Sept 2019
    6.1
    Medium

    CVE-2019-16118

    Last Modified: 10 Sept 2019

    Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.

    Source:MTK
    Published:8 Sept 2019
    6.1
    Medium

    CVE-2019-16117

    Last Modified: 10 Sept 2019

    Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.

    Source:MTK
    Published:8 Sept 2019
    4.3
    Medium

    CVE-2019-16116

    Last Modified: 10 Nov 2020

    EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.

    Source:1F98D
    Published:2 Oct 2019
    8.8
    High

    CVE-2019-16113

    Last Modified: 26 Jul 2020

    Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.

    Source:James Green
    Published:8 Sept 2019
    8.8
    High

    CVE-2019-16112

    Last Modified: 14 May 2020

    TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager URI.

    Source:Anthony Cole
    Published:13 May 2020
    7.8
    High

    CVE-2019-16098

    Last Modified: 21 Nov 2024

    The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

    Published:11 Sept 2019
    6.5
    Medium

    CVE-2019-16097

    Last Modified: 21 Nov 2024

    core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

    Published:8 Sept 2019
    9.8
    Critical

    CVE-2019-16072

    Last Modified: 11 Sept 2019

    An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

    Source:xerubus
    Published:19 Mar 2020
    8.8
    High

    CVE-2019-16068

    Last Modified: 11 Sept 2019

    A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.

    Source:xerubus
    Published:19 Mar 2020
    8.8
    High

    CVE-2019-16065

    Last Modified: 11 Sept 2019

    A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially execute system-based commands as the mysql user. This affects the search_pattern value of the manage_hosts_short.cgi script.

    Source:xerubus
    Published:19 Mar 2020
    6.3
    Medium

    CVE-2019-15999

    Last Modified: 8 Jan 2020

    A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.

    Source:hantwister
    Published:6 Jan 2020
    5.3
    Medium

    CVE-2019-15993

    Last Modified: 5 Apr 2023

    A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.

    Source:Ken Pyle
    Published:23 Sept 2020
    7.2
    High

    CVE-2019-15984

    Last Modified: 13 Mar 2020

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Source:mr_me
    Published:6 Jan 2020
    7.2
    High

    CVE-2019-15978

    Last Modified: 13 Mar 2020

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Source:mr_me
    Published:6 Jan 2020
    7.5
    High

    CVE-2019-15977

    Last Modified: 13 Mar 2020

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Source:mr_me
    Published:6 Jan 2020
    9.8
    Critical

    CVE-2019-15976

    Last Modified: 13 Mar 2020

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Source:mr_me
    Published:6 Jan 2020
    9.8
    Critical

    CVE-2019-15975

    Last Modified: 18 Mar 2020

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Source:mr_me
    Published:6 Jan 2020
    8.8
    High

    CVE-2019-15972

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious requests to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database.

    Published:26 Nov 2019
    9.9
    Critical

    CVE-2019-15954

    Last Modified: 22 Oct 2019

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

    Source:Metasploit
    Published:5 Sept 2019
    8.8
    High

    CVE-2019-15949

    Last Modified: 10 Mar 2020

    Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.

    Source:Metasploit
    Published:5 Sept 2019