9.8
    Critical

    CVE-2019-14893

    Last Modified: 21 Nov 2024

    A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.

    Published:20 Sept 2019
    9.8
    Critical

    CVE-2019-14892

    Last Modified: 21 Nov 2024

    A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.

    Published:19 Sept 2019
    6.1
    Medium

    CVE-2019-14830

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").

    Published:19 Mar 2021
    7.8
    High

    CVE-2019-14811

    Last Modified: 21 Nov 2024

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

    Published:28 Aug 2019
    4.8
    Medium

    CVE-2019-14804

    Last Modified: 12 Aug 2019

    studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.

    Source:Greg.Priest
    Published:9 Aug 2019
    7.5
    High

    CVE-2019-14751

    Last Modified: 21 Nov 2024

    NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

    Published:22 Aug 2019
    6.1
    Medium

    CVE-2019-14750

    Last Modified: 12 Aug 2019

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

    Source:Aishwarya Iyer
    Published:7 Aug 2019
    8.8
    High

    CVE-2019-14749

    Last Modified: 12 Aug 2019

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.

    Source:Aishwarya Iyer
    Published:7 Aug 2019
    5.4
    Medium

    CVE-2019-14748

    Last Modified: 12 Aug 2019

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.

    Source:Aishwarya Iyer
    Published:7 Aug 2019
    7.8
    High

    CVE-2019-14745

    Last Modified: 21 Nov 2024

    In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

    Published:7 Aug 2019
    7.8
    High

    CVE-2019-14737

    Last Modified: 15 Oct 2019

    Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.

    Source:Kusol Watchara-Apanukorn
    Published:14 Oct 2019
    6.1
    Medium

    CVE-2019-14696

    Last Modified: 8 Aug 2019

    Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

    Source:Greg.Priest
    Published:6 Aug 2019
    10
    Critical

    CVE-2019-14678

    Last Modified: 21 Nov 2024

    SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

    Published:14 Nov 2019
    5.5
    Medium

    CVE-2019-14615

    Last Modified: 21 Nov 2024

    Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

    Published:14 Jan 2020
    9.8
    Critical

    CVE-2019-14540

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.

    Published:15 Sept 2019
    9.8
    Critical

    CVE-2019-14537

    Last Modified: 21 Nov 2024

    YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

    Published:7 Aug 2019
    8.8
    High

    CVE-2019-14530

    Last Modified: 21 Jun 2021

    An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

    Source:Ron Jost
    Published:13 Aug 2019
    9.8
    Critical

    CVE-2019-14529

    Last Modified: 21 Nov 2024

    OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.

    Published:2 Aug 2019
    9.8
    Critical

    CVE-2019-14514

    Last Modified: 21 Nov 2024

    An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a closed-source proprietary tool that seems to be developed by Microvirt). This program opens TCP port 21509, presumably to receive installation-related commands from the host OS. Because everything after the installer:uninstall command is concatenated directly into a system() call, it is possible to execute arbitrary commands by supplying shell metacharacters.

    Published:10 Feb 2020
    6.1
    Medium

    CVE-2019-14470

    Last Modified: 26 Aug 2019

    cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.

    Source:Damian Ebelties
    Published:4 Sept 2019
    9.1
    Critical

    CVE-2019-14462

    Last Modified: 21 Nov 2024

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

    Published:31 Jul 2019
    9.8
    Critical

    CVE-2019-14450

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When this is combined with CVE-2019-14451, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.

    Published:28 Oct 2019
    7.5
    High

    CVE-2019-14439

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

    Published:30 Jul 2019
    5.3
    Medium

    CVE-2019-14430

    Last Modified: 19 Aug 2019

    plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.

    Source:Fabian Mosch
    Published:20 Aug 2019
    8.8
    High

    CVE-2019-14422

    Last Modified: 14 Aug 2019

    An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code. A tsvncmd:command:diff?path:[file1]?path2:[file2] URI will execute a customised diff on [file1] and [file2] based on the file extension. For xls files, it will execute the script diff-xls.js using wscript, which will open the two files for analysis without any macro security warning. An attacker can exploit this by putting a macro virus in a network drive, and force the victim to open the workbooks and execute the macro inside.

    Source:Vulnerability-Lab
    Published:15 Aug 2019
    9.8
    Critical

    CVE-2019-14379

    Last Modified: 21 Nov 2024

    SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

    Published:23 Jul 2019
    8.8
    High

    CVE-2019-14378

    Last Modified: 30 Aug 2019

    ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

    Source:vishnudevtj
    Published:28 Jul 2019
    9.8
    Critical

    CVE-2019-14348

    Last Modified: 7 Aug 2019

    The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.

    Source:Pablo Santiago
    Published:5 Aug 2019
    8.8
    High

    CVE-2019-14347

    Last Modified: 8 Nov 2019

    Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.

    Source:Pablo Santiago
    Published:6 Aug 2019
    8.8
    High

    CVE-2019-14346

    Last Modified: 8 Aug 2019

    Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.

    Source:Pablo Santiago
    Published:6 Aug 2019
    5.5
    Medium

    CVE-2019-14339

    Last Modified: 30 Aug 2019

    The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

    Source:0x48piraj
    Published:5 Sept 2019
    8.8
    High

    CVE-2019-14328

    Last Modified: 29 Jul 2019

    The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.

    Source:rubyman
    Published:28 Jul 2019
    7.8
    High

    CVE-2019-14326

    Last Modified: 21 Nov 2024

    An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the emulated Android system. This can be exploited by remote attackers to gain full access to the device, or by malicious apps installed inside the emulator to perform privilege escalation from a normal user to root (unlike with standard methods of getting root privileges on Android - e.g., the SuperSu program - the user is not asked for consent). There is no authentication performed - access to a root shell is given upon a successful connection. NOTE: although this was originally published with a slightly different CVE ID number, the correct ID for this Andy vulnerability has always been CVE-2019-14326.

    Published:14 Apr 2020
    7.5
    High

    CVE-2019-14322

    Last Modified: 6 Jul 2021

    In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

    Source:faisalfs10x
    Published:28 Jul 2019
    6.5
    Medium

    CVE-2019-14319

    Last Modified: 21 Nov 2024

    The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network traffic.

    Published:4 Sept 2019
    9.8
    Critical

    CVE-2019-14314

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

    Published:27 Aug 2019
    6.5
    Medium

    CVE-2019-14312

    Last Modified: 8 Aug 2019

    Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via a tools/sourceViewer/index.html?filename=../ URI.

    Source:Steph Jensen
    Published:9 Aug 2019
    8.8
    High

    CVE-2019-14287

    Last Modified: 17 Dec 2021

    In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.

    Source:Mohin Paramasivam
    Published:14 Oct 2019
    5.3
    Medium

    CVE-2019-14280

    Last Modified: 2 Sept 2019

    In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.

    Source:Mohammed Abdul Raheem
    Published:26 Jul 2019
    9.8
    Critical

    CVE-2019-14271

    Last Modified: 21 Nov 2024

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

    Published:29 Jul 2019
    7.8
    High

    CVE-2019-14267

    Last Modified: 26 Jul 2019

    PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.

    Source:j0lama
    Published:29 Jul 2019
    9.8
    Critical

    CVE-2019-14234

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.

    Published:1 Aug 2019
    7.2
    High

    CVE-2019-14224

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution on the victim machine. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.

    Published:5 Sept 2019
    6.1
    Medium

    CVE-2019-14223

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

    Published:6 Sept 2019
    9.8
    Critical

    CVE-2019-14222

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g., OS type, system file locations, Java version, Solr version, etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco's Solr Web Admin Interface.

    Published:5 Sept 2019
    5.4
    Medium

    CVE-2019-14221

    Last Modified: 2 Aug 2019

    1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

    Source:Kusol Watchara-Apanukorn
    Published:8 Aug 2019
    6.5
    Medium

    CVE-2019-14220

    Last Modified: 21 Nov 2024

    An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read

    Published:24 Sept 2019
    7.5
    High

    CVE-2019-14206

    Last Modified: 21 Nov 2024

    An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings'] parameter in adaptive-images-script.php.

    Published:21 Jul 2019
    7.8
    High

    CVE-2019-14079

    Last Modified: 21 Nov 2024

    Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the first place leading to kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, MDM9607, MDM9640, MSM8909W, MSM8953, QCA6574AU, QCS605, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX24, SM8150, SXR1130

    Published:5 Mar 2020
    7.8
    High

    CVE-2019-14041

    Last Modified: 21 Nov 2024

    During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

    Published:7 Feb 2020