7.8
    High

    CVE-2019-14040

    Last Modified: 21 Nov 2024

    Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150, SXR1130

    Published:7 Feb 2020
    9.8
    Critical

    CVE-2019-13990

    Last Modified: 21 Nov 2024

    initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

    Published:26 Jul 2019
    5.4
    Medium

    CVE-2019-13977

    Last Modified: 25 Jul 2019

    index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.

    Source:n3k00n3
    Published:19 Jul 2019
    8.8
    High

    CVE-2019-13961

    Last Modified: 13 Apr 2025

    A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.

    Source:CodeSecLab
    Published:18 Jul 2019
    9.8
    Critical

    CVE-2019-13956

    Last Modified: 21 Nov 2024

    Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).

    Published:18 Jul 2019
    8.8
    High

    CVE-2019-13764

    Last Modified: 21 Nov 2024

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:10 Dec 2019
    8.8
    High

    CVE-2019-13720

    Last Modified: 11 May 2022

    Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Forrest Orr
    Published:29 Oct 2019
    6.1
    Medium

    CVE-2019-13633

    Last Modified: 21 Nov 2024

    Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-in communication channel, such as Telegram, WhatsApp, Viber, Skype, Facebook, Vkontakte, or Odnoklassniki. This is mishandled within the administration panel for conversations/all, conversations/inbox, conversations/unassigned, and conversations/closed.

    Published:19 Oct 2020
    7.8
    High

    CVE-2019-13623

    Last Modified: 8 Apr 2021

    In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.

    Source:Etienne Lacoche
    Published:17 Jul 2019
    8.8
    High

    CVE-2019-13605

    Last Modified: 16 Jul 2019

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveraging the knowledge of a valid username. The attacker must defeat an encoding that is not equivalent to base64, and thus this is different from CVE-2019-13360.

    Source:Pongtorn Angsuchotmetee
    Published:16 Jul 2019
    9.8
    Critical

    CVE-2019-13597

    Last Modified: 16 Jul 2019

    _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can create a new script with an editor. It is possible to execute commands on the server using the _execute() function.

    Source:AkkuS
    Published:14 Jul 2019
    9.8
    Critical

    CVE-2019-13577

    Last Modified: 20 Jul 2019

    SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.

    Source:hyp3rlinx
    Published:17 Jul 2019
    7.8
    High

    CVE-2019-13574

    Last Modified: 21 Nov 2024

    In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.

    Published:12 Jul 2019
    8.8
    High

    CVE-2019-13529

    Last Modified: 10 Oct 2019

    An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.

    Source:Borja Merino
    Published:9 Oct 2019
    7.4
    High

    CVE-2019-13498

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.

    Published:29 Jul 2019
    6.5
    Medium

    CVE-2019-13497

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

    Published:4 Nov 2019
    8.1
    High

    CVE-2019-13496

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

    Published:4 Nov 2019
    7.8
    High

    CVE-2019-13494

    Last Modified: 12 Jul 2019

    nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.

    Source:xerubus
    Published:12 Jul 2019
    5.4
    Medium

    CVE-2019-13493

    Last Modified: 11 Jul 2019

    In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.

    Source:Owais Mehtab
    Published:17 Jul 2019
    Unknown

    CVE-2019-13491

    https://www.exploit-db.com/exploits/47107

    7.5
    High

    CVE-2019-13403

    Last Modified: 21 Nov 2024

    Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leading to the viewing of user information.

    Published:17 Jul 2019
    5.3
    Medium

    CVE-2019-13396

    Last Modified: 15 Jul 2019

    FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.

    Source:Mohammed Althibyani
    Published:10 Jul 2019
    5.3
    Medium

    CVE-2019-13383

    Last Modified: 16 Jul 2019

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a username is valid by reading the HTTP response.

    Source:Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Narin Boonwasanarak
    Published:16 Jul 2019
    6.5
    Medium

    CVE-2019-13361

    Last Modified: 21 Nov 2024

    Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

    Published:5 Sept 2019
    9.8
    Critical

    CVE-2019-13360

    Last Modified: 16 Jul 2019

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.

    Source:Pongtorn Angsuchotmetee
    Published:16 Jul 2019
    7.5
    High

    CVE-2019-13359

    Last Modified: 16 Jul 2019

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and upload a session file to the /tmp directory, and use it to become the root user.

    Source:Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Narin Boonwasanarak
    Published:16 Jul 2019
    7.5
    High

    CVE-2019-13358

    Last Modified: 27 Sept 2021

    lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.

    Source:Jake Ruston
    Published:5 Jul 2019
    6.1
    Medium

    CVE-2019-13346

    Last Modified: 12 Jul 2019

    In MyT 1.5.1, the User[username] parameter has XSS.

    Source:Metin Yunus Kandemir
    Published:17 Jul 2019
    5.3
    Medium

    CVE-2019-13344

    Last Modified: 9 Jul 2019

    An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

    Source:Benjamin Lim
    Published:5 Jul 2019
    9.8
    Critical

    CVE-2019-13294

    Last Modified: 5 Jul 2019

    AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

    Source:AkkuS
    Published:4 Jul 2019
    9.8
    Critical

    CVE-2019-13292

    Last Modified: 5 Jul 2019

    A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

    Source:Semen Alexandrovich Lyhin
    Published:4 Jul 2019
    5.5
    Medium

    CVE-2019-13288

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

    Published:4 Jul 2019
    7.8
    High

    CVE-2019-13272

    Last Modified: 17 Jul 2019

    In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

    Source:Google Security Research
    Published:16 Jul 2019
    4.3
    Medium

    CVE-2019-13237

    Last Modified: 2 Sept 2019

    In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp, xmlcontentrepair.jsp, and /system/workplace/admin/history/settings/index.jsp.

    Source:Aetsu
    Published:27 Aug 2019
    6.1
    Medium

    CVE-2019-13236

    Last Modified: 2 Sept 2019

    In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.

    Source:Aetsu
    Published:27 Aug 2019
    6.1
    Medium

    CVE-2019-13235

    Last Modified: 2 Sept 2019

    In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.

    Source:Aetsu
    Published:27 Aug 2019
    6.1
    Medium

    CVE-2019-13234

    Last Modified: 2 Sept 2019

    In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.

    Source:Aetsu
    Published:27 Aug 2019
    9.8
    Critical

    CVE-2019-13144

    Last Modified: 21 Nov 2024

    myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.

    Published:5 Jul 2019
    9.8
    Critical

    CVE-2019-13143

    Last Modified: 21 Nov 2024

    An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

    Published:6 Aug 2019
    9.8
    Critical

    CVE-2019-13132

    Last Modified: 21 Nov 2024

    In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.

    Published:10 Jul 2019
    8.1
    High

    CVE-2019-13115

    Last Modified: 21 Nov 2024

    In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.

    Published:16 Jul 2019
    9.8
    Critical

    CVE-2019-13101

    Last Modified: 14 Aug 2019

    An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

    Source:Devendra Singh Solanki
    Published:8 Aug 2019
    9.8
    Critical

    CVE-2019-13086

    Last Modified: 21 Nov 2024

    core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.

    Published:30 Jun 2019
    7.8
    High

    CVE-2019-13069

    Last Modified: 20 Aug 2019

    extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an additional user account, and then use SSH and port forwarding to reach a 127.0.0.1 service.

    Source:Ian Bredemeyer
    Published:17 Aug 2019
    5.4
    Medium

    CVE-2019-13068

    Last Modified: 9 Jun 2023

    public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

    Source:SimranJeet Singh
    Published:29 Jun 2019
    7.5
    High

    CVE-2019-13063

    Last Modified: 9 Mar 2020

    Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.

    Source:Operat0r
    Published:23 Sept 2019
    8.8
    High

    CVE-2019-13051

    Last Modified: 21 Nov 2024

    Pi-Hole 4.3 allows Command Injection.

    Published:9 Oct 2019
    4.8
    Medium

    CVE-2019-13029

    Last Modified: 19 Jul 2019

    Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.

    Source:Alexandre ZANNI
    Published:11 Jul 2019
    9.8
    Critical

    CVE-2019-13027

    Last Modified: 21 Nov 2024

    Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.

    Published:12 Jul 2019
    9.8
    Critical

    CVE-2019-13025

    Last Modified: 21 Nov 2024

    Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be executed on the device, to an backend API endpoint of the cable modem.

    Published:2 Oct 2019