6.1
    Medium

    CVE-2019-10846

    Last Modified: 12 Nov 2019

    Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via the username GET parameter.

    Source:LiquidWorm
    Published:23 May 2019
    Low

    CVE-2019-10843

    Last Modified: 4 Apr 2019

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:Anurag Srivastava
    Published:10 Apr 2019
    6.1
    Medium

    CVE-2019-10779

    Last Modified: 21 Nov 2024

    All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via an XSS vulnerability to take full control of the Stroom UI on behalf of the logged-in user.

    Published:28 Jan 2020
    9.9
    Critical

    CVE-2019-10760

    Last Modified: 21 Nov 2024

    safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.

    Published:15 Oct 2019
    9.9
    Critical

    CVE-2019-10758

    Last Modified: 27 Oct 2025

    mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

    Published:24 Dec 2019
    9.1
    Critical

    CVE-2019-10744

    Last Modified: 21 Nov 2024

    Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

    Published:25 Jul 2019
    5.5
    Medium

    CVE-2019-10743

    Last Modified: 21 Nov 2024

    All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the final path ending up outside of the target folder. For instance, a zip may hold a file with a "../../file.exe" location and thus break out of the target folder. If an executable or a configuration file is overwritten with a file containing malicious code, the problem can turn into an arbitrary code execution issue quite easily.

    Published:12 May 2019
    7.5
    High

    CVE-2019-10742

    Last Modified: 21 Nov 2024

    Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.

    Published:7 May 2019
    7.7
    High

    CVE-2019-10716

    Last Modified: 5 Feb 2020

    An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security technologies via a /integrations.json JSON REST API request.

    Source:nxkennedy
    Published:20 Oct 2019
    9.8
    Critical

    CVE-2019-10709

    Last Modified: 30 Aug 2019

    AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.

    Source:Athanasios Tserpelis
    Published:4 Sept 2019
    9.8
    Critical

    CVE-2019-10708

    Last Modified: 21 Nov 2024

    S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.

    Published:2 Apr 2019
    6.1
    Medium

    CVE-2019-10685

    Last Modified: 7 May 2019

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.

    Source:alt3kx
    Published:24 May 2019
    7.5
    High

    CVE-2019-10678

    Last Modified: 30 Apr 2019

    Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.

    Source:Fabio Carretto
    Published:31 Mar 2019
    6.1
    Medium

    CVE-2019-10677

    Last Modified: 4 Sept 2019

    Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).

    Source:Adam Ziaja
    Published:5 Sept 2019
    7.2
    High

    CVE-2019-10669

    Last Modified: 10 Sept 2019

    An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where user supplied parameters are filtered with the mysqli_escape_real_string function. This function is not the appropriate function to sanitize command arguments as it does not escape a number of command line syntax characters such as ` (backtick), allowing an attacker to inject commands into the variable $rrd_cmd, which gets executed via passthru().

    Source:Metasploit
    Published:9 Sept 2019
    9.8
    Critical

    CVE-2019-10664

    Last Modified: 30 Apr 2019

    Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.

    Source:Fabio Carretto
    Published:31 Mar 2019
    7.2
    High

    CVE-2019-10652

    Last Modified: 13 Apr 2025

    An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.

    Source:CodeSecLab
    Published:30 Mar 2019
    8.1
    High

    CVE-2019-10529

    Last Modified: 29 May 2019

    Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

    Source:Google Security Research
    Published:6 Nov 2019
    6.1
    Medium

    CVE-2019-10475

    Last Modified: 8 Nov 2019

    A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

    Source:vesche
    Published:23 Oct 2019
    8.8
    High

    CVE-2019-10392

    Last Modified: 21 Nov 2024

    Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.

    Published:12 Sept 2019
    5.4
    Medium

    CVE-2019-10349

    Last Modified: 12 Jul 2019

    A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

    Source:Ishaq Mohammed
    Published:11 Jul 2019
    4.3
    Medium

    CVE-2019-10273

    Last Modified: 9 Mar 2020

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

    Source:Operat0r
    Published:4 Apr 2019
    8.8
    High

    CVE-2019-10267

    Last Modified: 26 Jul 2019

    An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).

    Source:Wietse Boonstra
    Published:26 Jul 2019
    7.5
    High

    CVE-2019-10266

    Last Modified: 26 Jul 2019

    An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication.

    Source:Wietse Boonstra
    Published:26 Jul 2019
    4.8
    Medium

    CVE-2019-10261

    Last Modified: 29 Mar 2019

    CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.

    Source:DKM
    Published:3 Apr 2019
    6.1
    Medium

    CVE-2019-10227

    Last Modified: 26 Aug 2019

    openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.

    Source:Julian Rittweger
    Published:31 Dec 2019
    5.4
    Medium

    CVE-2019-10226

    Last Modified: 29 Mar 2019

    HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is a XSS protection mechanism.

    Source:Ismail Tasdelen
    Published:10 Jun 2019
    8.8
    High

    CVE-2019-10220

    Last Modified: 21 Nov 2024

    Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

    Published:27 Nov 2019
    6.1
    Medium

    CVE-2019-10219

    Last Modified: 25 Aug 2026

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

    Published:28 Aug 2019
    5.5
    Medium

    CVE-2019-10207

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.

    Published:29 Jul 2019
    7.5
    High

    CVE-2019-10172

    Last Modified: 21 Nov 2024

    A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

    Published:18 Nov 2019
    9.8
    Critical

    CVE-2019-10149

    Last Modified: 26 Aug 2019

    A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

    Source:Marco Ivaldi
    Published:4 Jun 2019
    9.8
    Critical

    CVE-2019-10123

    Last Modified: 30 Apr 2019

    SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user.

    Source:Metasploit
    Published:31 May 2019
    6.1
    Medium

    CVE-2019-10098

    Last Modified: 19 Nov 2019

    In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

    Source:Sebastian Neef
    Published:14 Aug 2019
    6.1
    Medium

    CVE-2019-10092

    Last Modified: 19 Nov 2019

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

    Source:Sebastian Neef
    Published:14 Aug 2019
    6.1
    Medium

    CVE-2019-10089

    Last Modified: 21 Nov 2024

    On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.

    Published:23 Sept 2019
    7.3
    High

    CVE-2019-10086

    Last Modified: 25 Aug 2026

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

    Published:15 Aug 2019
    6.1
    Medium

    CVE-2019-10078

    Last Modified: 21 Nov 2024

    A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.

    Published:20 May 2019
    6.1
    Medium

    CVE-2019-10077

    Last Modified: 21 Nov 2024

    A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

    Published:20 May 2019
    6.1
    Medium

    CVE-2019-10076

    Last Modified: 21 Nov 2024

    A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

    Published:20 May 2019
    6.1
    Medium

    CVE-2019-10070

    Last Modified: 21 Nov 2024

    Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

    Published:18 Nov 2019
    9.8
    Critical

    CVE-2019-10068

    Last Modified: 19 Dec 2025

    An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

    Published:26 Mar 2019
    7.8
    High

    CVE-2019-10038

    Last Modified: 18 Apr 2019

    Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file.

    Source:Dhiraj Mishra
    Published:31 May 2019
    6.5
    Medium

    CVE-2019-10009

    Last Modified: 26 Mar 2019

    A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory.

    Source:Kevin Randall
    Published:3 Jun 2019
    8.8
    High

    CVE-2019-10008

    Last Modified: 15 Apr 2019

    Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

    Source:Ata Hakçıl_ Melih Kaan Yıldız
    Published:24 Apr 2019
    6.1
    Medium

    CVE-2019-9978

    Last Modified: 26 Jun 2025

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

    Source:Huseyin Mardinli
    Published:24 Mar 2019
    6.1
    Medium

    CVE-2019-9955

    Last Modified: 16 Apr 2019

    On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

    Source:Aaron Bishop
    Published:22 Apr 2019
    7.8
    High

    CVE-2019-9896

    Last Modified: 21 Nov 2024

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.

    Published:21 Mar 2019
    5.3
    Medium

    CVE-2019-9881

    Last Modified: 21 May 2019

    The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.

    Source:Simone Quatrini
    Published:10 Jun 2019
    9.1
    Critical

    CVE-2019-9880

    Last Modified: 21 May 2019

    An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.

    Source:Simone Quatrini
    Published:10 Jun 2019