8.8
    High

    CVE-2019-15943

    Last Modified: 2 Oct 2019

    vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset call.

    Source:bi7s
    Published:19 Sept 2019
    9.8
    Critical

    CVE-2019-15896

    Last Modified: 21 Nov 2024

    An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.

    Published:10 Sept 2019
    6.1
    Medium

    CVE-2019-15889

    Last Modified: 4 Sept 2019

    The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.

    Source:MgThuraMoeMyint
    Published:3 Sept 2019
    8.8
    High

    CVE-2019-15858

    Last Modified: 21 Nov 2024

    admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code execution.

    Published:3 Sept 2019
    9.8
    Critical

    CVE-2019-15846

    Last Modified: 21 Nov 2024

    Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

    Published:6 Sept 2019
    5.4
    Medium

    CVE-2019-15814

    Last Modified: 30 Aug 2019

    Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.

    Source:creosote
    Published:4 Sept 2019
    8.8
    High

    CVE-2019-15813

    Last Modified: 30 Aug 2019

    Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.

    Source:creosote
    Published:4 Sept 2019
    6.1
    Medium

    CVE-2019-15811

    Last Modified: 30 Aug 2019

    In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.

    Source:Damian Ebelties
    Published:29 Aug 2019
    7.1
    High

    CVE-2019-15794

    Last Modified: 20 Nov 2019

    Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is not an issue, as no callers dereference vm_file following after call_mmap() returns an error. However, the aufs patchs change mmap_region() to replace the fput() using a local variable with vma_fput(), which will fput() vm_file, leading to a refcount underflow.

    Source:Google Security Research
    Published:12 Nov 2019
    6.5
    Medium

    CVE-2019-15793

    Last Modified: 20 Nov 2019

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This resulted in using ids other than the intended ones in the lower fs, which likely did not map into the shifts s_user_ns. A local attacker could use this to possibly bypass discretionary access control permissions.

    Source:Google Security Research
    Published:23 Apr 2020
    7.1
    High

    CVE-2019-15792

    Last Modified: 20 Nov 2019

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info *". As the private_data is not required to be a pointer, an attacker can use this to cause a denial of service or possibly execute arbitrary code.

    Source:Google Security Research
    Published:23 Apr 2020
    7.1
    High

    CVE-2019-15791

    Last Modified: 20 Nov 2019

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a reference to that file, leading to a refcount underflow.

    Source:Google Security Research
    Published:1 Nov 2019
    7.8
    High

    CVE-2019-15752

    Last Modified: 28 Apr 2020

    Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.

    Source:Metasploit
    Published:28 Aug 2019
    7.8
    High

    CVE-2019-15742

    Last Modified: 17 Jan 2020

    A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit this issue to gain elevated privileges.

    Source:Metasploit
    Published:16 Jan 2020
    7.2
    High

    CVE-2019-15715

    Last Modified: 18 Sept 2020

    MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.

    Source:Nikolas Geiselman
    Published:9 Oct 2019
    4.9
    Medium

    CVE-2019-15707

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.

    Published:23 Jan 2020
    8.8
    High

    CVE-2019-15642

    Last Modified: 21 Nov 2024

    rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

    Published:26 Aug 2019
    8.1
    High

    CVE-2019-15637

    Last Modified: 27 Aug 2019

    Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.

    Source:Jarad Kopf
    Published:26 Aug 2019
    7.1
    High

    CVE-2019-15627

    Last Modified: 6 Dec 2019

    Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to availability impact. Local OS access is required. Please note that only Windows agents are affected.

    Source:Peter Lapp
    Published:17 Oct 2019
    9.8
    Critical

    CVE-2019-15605

    Last Modified: 30 Apr 2025

    HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

    Published:7 Feb 2020
    7.2
    High

    CVE-2019-15588

    Last Modified: 21 Nov 2024

    There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.

    Published:1 Nov 2019
    5.3
    Medium

    CVE-2019-15514

    Last Modified: 21 Nov 2024

    The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction of a region's assigned phone numbers.

    Published:23 Aug 2019
    7.8
    High

    CVE-2019-15511

    Last Modified: 21 Nov 2024

    An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

    Published:21 Nov 2019
    6.1
    Medium

    CVE-2019-15501

    Last Modified: 26 Aug 2019

    Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

    Source:MTK
    Published:26 Aug 2019
    6.1
    Medium

    CVE-2019-15477

    Last Modified: 21 Nov 2024

    Jooby before 1.6.4 has XSS via the default error handler.

    Published:23 Aug 2019
    6.5
    Medium

    CVE-2019-15276

    Last Modified: 4 Dec 2019

    A vulnerability in the web interface of Cisco Wireless LAN Controller Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists due to a failure of the HTTP parsing engine to handle specially crafted URLs. An attacker could exploit this vulnerability by authenticating with low privileges to an affected controller and submitting the crafted URL to the web interface of the affected device. Conversely, an unauthenticated attacker could exploit this vulnerability by persuading a user of the web interface to click the crafted URL. A successful exploit could allow the attacker to cause an unexpected restart of the device, resulting in a DoS condition.

    Source:SecuNinja
    Published:26 Nov 2019
    4.8
    Medium

    CVE-2019-15253

    Last Modified: 14 May 2020

    A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs administrator credentials. This vulnerability affects Cisco DNA Center Software releases earlier than 1.3.0.6 and 1.3.1.4.

    Source:Dylan Garnaud
    Published:5 Feb 2020
    6.1
    Medium

    CVE-2019-15233

    Last Modified: 21 Nov 2024

    The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.

    Published:20 Aug 2019
    Low

    CVE-2019-15231

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of CVE-2019-15107. Notes: All CVE users should reference CVE-2019-15107 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published:19 Aug 2019
    9.8
    Critical

    CVE-2019-15224

    Last Modified: 21 Nov 2024

    The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

    Published:19 Aug 2019
    1.6
    Low

    CVE-2019-15166

    Last Modified: 3 Dec 2025

    lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

    Published:2 Oct 2019
    3.1
    Low

    CVE-2019-15126

    Last Modified: 19 Mar 2020

    An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

    Source:Maurizio S
    Published:5 Feb 2020
    5.4
    Medium

    CVE-2019-15120

    Last Modified: 21 Nov 2024

    The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

    Published:16 Aug 2019
    9.8
    Critical

    CVE-2019-15107

    Last Modified: 26 Aug 2019

    An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

    Source:AkkuS
    Published:16 Aug 2019
    9.8
    Critical

    CVE-2019-15106

    Last Modified: 28 Aug 2019

    An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.

    Source:AkkuS
    Published:16 Aug 2019
    8.8
    High

    CVE-2019-15105

    Last Modified: 28 Aug 2019

    An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

    Source:AkkuS
    Published:16 Aug 2019
    8.8
    High

    CVE-2019-15104

    Last Modified: 28 Aug 2019

    An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.

    Source:AkkuS
    Published:16 Aug 2019
    7.3
    High

    CVE-2019-15092

    Last Modified: 26 Aug 2019

    The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.

    Source:Javier Olmedo
    Published:23 Aug 2019
    7.8
    High

    CVE-2019-15084

    Last Modified: 28 Nov 2019

    Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.

    Source:Mike Siegel
    Published:15 Aug 2019
    6.1
    Medium

    CVE-2019-15083

    Last Modified: 15 May 2020

    Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.

    Source:Felipe Molina
    Published:14 May 2020
    4.8
    Medium

    CVE-2019-15081

    Last Modified: 2 Sept 2019

    OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.

    Source:Nipun Somani
    Published:15 Aug 2019
    6.8
    Medium

    CVE-2019-15053

    Last Modified: 21 Nov 2024

    The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.

    Published:14 Aug 2019
    7.5
    High

    CVE-2019-15043

    Last Modified: 21 Nov 2024

    In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

    Published:29 Aug 2019
    9.8
    Critical

    CVE-2019-15039

    Last Modified: 13 Apr 2020

    An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.

    Source:hantwister
    Published:1 Oct 2019
    8.8
    High

    CVE-2019-15029

    Last Modified: 9 Sept 2019

    FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request with the service id followed by the parameter a=start to execute the stored command.

    Source:Askar
    Published:5 Sept 2019
    6.1
    Medium

    CVE-2019-14974

    Last Modified: 14 Aug 2019

    SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.

    Source:Ilca Lucian Florin
    Published:14 Aug 2019
    9.8
    Critical

    CVE-2019-14931

    Last Modified: 14 Aug 2019

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

    Source:xerubus
    Published:28 Oct 2019
    7.5
    High

    CVE-2019-14927

    Last Modified: 14 Aug 2019

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

    Source:xerubus
    Published:28 Oct 2019
    6.1
    Medium

    CVE-2019-14912

    Last Modified: 21 Nov 2024

    An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.

    Published:20 Sept 2019
    6.5
    Medium

    CVE-2019-14900

    Last Modified: 21 Nov 2024

    A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

    Published:12 May 2020