9.8
    Critical

    CVE-2019-11448

    Last Modified: 22 Apr 2019

    An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.

    Source:AkkuS
    Published:22 Apr 2019
    8.8
    High

    CVE-2019-11447

    Last Modified: 18 Mar 2021

    An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)

    Source:AkkuS
    Published:22 Apr 2019
    8.8
    High

    CVE-2019-11446

    Last Modified: 22 Apr 2019

    An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The Upload Files section in the File Manager field contains an arbitrary file upload vulnerability via upload.php. The $IllegalExtensions value only lists lowercase (and thus .phP is a bypass), and omits .shtml and .phtml.

    Source:AkkuS
    Published:22 Apr 2019
    7.2
    High

    CVE-2019-11445

    Last Modified: 22 Apr 2019

    OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home directory of the site, via frontend/FileUpload and admin/repository_export.jsp. This is achieved by interfering with the Filesystem path control in the admin's Export field. As a result, attackers can gain remote code execution through the application server with root privileges.

    Source:AkkuS
    Published:22 Apr 2019
    7.2
    High

    CVE-2019-11444

    Last Modified: 22 Apr 2019

    An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account are required. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw

    Source:AkkuS
    Published:22 Apr 2019
    4.8
    Medium

    CVE-2019-11429

    Last Modified: 1 May 2019

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to Reflected XSS for the "Domain" field on the "DNS Functions > "Add DNS Zone" screen.

    Source:DKM
    Published:13 May 2019
    5.5
    Medium

    CVE-2019-11419

    Last Modified: 16 May 2019

    vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file. The content of the replacement must be derived from the phone's IMEI. The crash occurs upon receiving a message that contains the replaced emoji.

    Source:Hong Nhat Pham
    Published:14 May 2019
    8.8
    High

    CVE-2019-11416

    Last Modified: 30 Apr 2019

    A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.

    Source:Social Engineering Neo
    Published:21 Apr 2019
    7.5
    High

    CVE-2019-11415

    Last Modified: 30 Apr 2019

    An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.

    Source:Social Engineering Neo
    Published:21 Apr 2019
    8.8
    High

    CVE-2019-11409

    Last Modified: 20 Nov 2019

    app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host. This can further lead to remote code execution when combined with an XSS vulnerability also present in the FusionPBX Operator Panel module.

    Source:Metasploit
    Published:17 Jun 2019
    6.1
    Medium

    CVE-2019-11408

    Last Modified: 21 Nov 2024

    XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject arbitrary JavaScript characters by placing a phone call using a specially crafted caller ID number. This can further lead to remote code execution by chaining this vulnerability with a command injection vulnerability also present in FusionPBX.

    Published:17 Jun 2019
    6.1
    Medium

    CVE-2019-11398

    Last Modified: 10 Jun 2019

    Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.

    Source:Unk9vvN
    Published:8 May 2019
    9.8
    Critical

    CVE-2019-11395

    Last Modified: 21 Nov 2024

    A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT TO, POP3 USER, POP3 LIST, POP3 TOP, or POP3 RETR.

    Published:21 Apr 2019
    6.5
    Medium

    CVE-2019-11375

    Last Modified: 22 Apr 2019

    Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.

    Source:ax8
    Published:20 Apr 2019
    8.8
    High

    CVE-2019-11374

    Last Modified: 22 Apr 2019

    74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

    Source:ax8
    Published:20 Apr 2019
    5.4
    Medium

    CVE-2019-11370

    Last Modified: 29 May 2019

    Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

    Source:Luca.Chiou
    Published:3 Jun 2019
    8.8
    High

    CVE-2019-11369

    Last Modified: 29 May 2019

    An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.

    Source:Luca.Chiou
    Published:3 Jun 2019
    5.4
    Medium

    CVE-2019-11368

    Last Modified: 29 May 2019

    Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.

    Source:Luca.Chiou
    Published:3 Jun 2019
    6.1
    Medium

    CVE-2019-11358

    Last Modified: 8 Apr 2025

    jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.

    Source:xOryus
    Published:27 Mar 2019
    7.8
    High

    CVE-2019-11354

    Last Modified: 24 Jun 2019

    The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.

    Source:Metin Yunus Kandemir
    Published:19 Apr 2019
    7.5
    High

    CVE-2019-11287

    Last Modified: 2 Apr 2025

    Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

    Published:22 Nov 2019
    5.4
    Medium

    CVE-2019-11269

    Last Modified: 17 Jun 2019

    Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.

    Source:Riemann
    Published:30 May 2019
    9.8
    Critical

    CVE-2019-11231

    Last Modified: 20 May 2019

    An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official documentation for installation step 10, an admin is required to upload all the files, including the .htaccess files, and run a health check. However, what is overlooked is that the Apache HTTP Server by default no longer enables the AllowOverride directive, leading to data/users/admin.xml password exposure. The passwords are hashed but this can be bypassed by starting with the data/other/authorization.xml API key. This allows one to target the session state, since they decided to roll their own implementation. The cookie_name is crafted information that can be leaked from the frontend (site name and version). If a someone leaks the API key and the admin username, then they can bypass authentication. To do so, they need to supply a cookie based on an SHA-1 computation of this known information. The vulnerability exists in the admin/theme-edit.php file. This file checks for forms submissions via POST requests, and for the csrf nonce. If the nonce sent is correct, then the file provided by the user is uploaded. There is a path traversal allowing write access outside the jailed themes directory root. Exploiting the traversal is not necessary because the .htaccess file is ignored. A contributing factor is that there isn't another check on the extension before saving the file, with the assumption that the parameter content is safe. This allows the creation of web accessible and executable files with arbitrary content.

    Source:Metasploit
    Published:22 May 2019
    8.8
    High

    CVE-2019-11229

    Last Modified: 1 Apr 2021

    models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

    Source:1F98D
    Published:13 Apr 2019
    8.8
    High

    CVE-2019-11224

    Last Modified: 21 Nov 2024

    HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.

    Published:15 May 2019
    9.8
    Critical

    CVE-2019-11223

    Last Modified: 21 Nov 2024

    An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

    Published:18 Apr 2019
    6.1
    Medium

    CVE-2019-11193

    Last Modified: 15 Apr 2019

    The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.

    Source:InfinitumIT
    Published:30 Apr 2019
    6.7
    Medium

    CVE-2019-11157

    Last Modified: 21 Nov 2024

    Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.

    Published:16 Dec 2019
    8.8
    High

    CVE-2019-11080

    Last Modified: 13 Jun 2019

    Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.

    Source:Jarad Kopf
    Published:6 Jun 2019
    9.8
    Critical

    CVE-2019-11076

    Last Modified: 21 Nov 2024

    Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.

    Published:23 Apr 2019
    10
    Critical

    CVE-2019-11061

    Last Modified: 21 Nov 2024

    A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself via http://[target]/smarthome/devicecontrol without any authentication. CVSS 3.0 base score 10 (Confidentiality, Integrity and Availability impacts). CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

    Published:29 Aug 2019
    8.7
    High

    CVE-2019-11043

    Last Modified: 9 Mar 2020

    In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

    Source:Metasploit
    Published:24 Oct 2019
    4.8
    Medium

    CVE-2019-11017

    Last Modified: 10 Apr 2019

    On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.

    Source:Semen Alexandrovich Lyhin
    Published:18 Apr 2019
    6.5
    Medium

    CVE-2019-11013

    Last Modified: 23 Aug 2019

    Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.

    Source:MaYaSeVeN
    Published:22 Aug 2019
    8.8
    High

    CVE-2019-10999

    Last Modified: 21 Nov 2024

    The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting wireless.htm. Vulnerable devices include DCS-5009L (1.08.11 and below), DCS-5010L (1.14.09 and below), DCS-5020L (1.15.12 and below), DCS-5025L (1.03.07 and below), DCS-5030L (1.04.10 and below), DCS-930L (2.16.01 and below), DCS-931L (1.14.11 and below), DCS-932L (2.17.01 and below), DCS-933L (1.14.11 and below), and DCS-934L (1.05.04 and below).

    Published:6 May 2019
    7.2
    High

    CVE-2019-10969

    Last Modified: 22 Oct 2019

    Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.

    Source:RandoriSec
    Published:8 Oct 2019
    4.3
    Medium

    CVE-2019-10963

    Last Modified: 22 Oct 2019

    Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.

    Source:RandoriSec
    Published:8 Oct 2019
    9.8
    Critical

    CVE-2019-10945

    Last Modified: 16 Apr 2019

    An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.

    Source:Haboob Team
    Published:10 Apr 2019
    7.8
    High

    CVE-2019-10915

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA Administrator) allows to execute certain application commands without proper authentication. The vulnerability could be exploited by an attacker with local access to the affected system. Successful exploitation requires no privileges and no user interaction. An attacker could use the vulnerability to compromise confidentiality and integrity and availability of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published:11 Jul 2019
    5.4
    Medium

    CVE-2019-10909

    Last Modified: 21 Nov 2024

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

    Published:16 May 2019
    4.8
    Medium

    CVE-2019-10893

    Last Modified: 1 May 2019

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.

    Source:DKM
    Published:18 Apr 2019
    6.1
    Medium

    CVE-2019-10887

    Last Modified: 8 Apr 2019

    A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows remote attackers to inject arbitrary HTML elements via a /DataLog.csv?log= or /AlarmLog.csv?log= or /waitlog.cgi?name= or /chart.shtml?data= or /createlog.cgi?name= request.

    Source:Ramikan
    Published:5 Apr 2019
    8.8
    High

    CVE-2019-10874

    Last Modified: 8 Apr 2019

    Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.

    Source:FelipeGaspar
    Published:5 Apr 2019
    8.1
    High

    CVE-2019-10869

    Last Modified: 17 Aug 2026

    Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.

    Published:7 May 2019
    8.8
    High

    CVE-2019-10867

    Last Modified: 30 Apr 2019

    An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to bundles/AdminBundle/Controller/Admin/DataObject/ClassController.php.

    Source:Metasploit
    Published:4 Apr 2019
    9.8
    Critical

    CVE-2019-10866

    Last Modified: 3 Jun 2019

    In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

    Source:Daniele Scanu
    Published:23 May 2019
    7.2
    High

    CVE-2019-10863

    Last Modified: 19 Apr 2019

    A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.

    Source:AkkuS
    Published:4 Apr 2019
    7.5
    High

    CVE-2019-10849

    Last Modified: 12 Nov 2019

    Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.

    Source:LiquidWorm
    Published:23 May 2019
    5.3
    Medium

    CVE-2019-10848

    Last Modified: 12 Nov 2019

    Computrols CBAS 18.0.0 allows Username Enumeration.

    Source:LiquidWorm
    Published:24 May 2019
    8.8
    High

    CVE-2019-10847

    Last Modified: 12 Nov 2019

    Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.

    Source:LiquidWorm
    Published:24 May 2019