9.8
    Critical

    CVE-2019-9879

    Last Modified: 21 May 2019

    The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.

    Source:Simone Quatrini
    Published:10 Jun 2019
    9.8
    Critical

    CVE-2019-9851

    Last Modified: 21 Aug 2019

    LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

    Source:LoadLow
    Published:15 Aug 2019
    4.3
    Medium

    CVE-2019-9849

    Last Modified: 21 Nov 2024

    LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

    Published:17 Jul 2019
    6.1
    Medium

    CVE-2019-9834

    Last Modified: 18 Mar 2019

    The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot

    Source:s4vitar
    Published:15 Mar 2019
    7.5
    High

    CVE-2019-9833

    Last Modified: 18 Mar 2019

    The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous /start-stop requests.

    Source:s4vitar
    Published:15 Mar 2019
    7.5
    High

    CVE-2019-9832

    Last Modified: 18 Mar 2019

    The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections through a configured port.

    Source:s4vitar
    Published:15 Mar 2019
    7.5
    High

    CVE-2019-9831

    Last Modified: 18 Mar 2019

    The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via many simultaneous /?Key=PhoneRequestAuthorization requests.

    Source:s4vitar
    Published:15 Mar 2019
    5.9
    Medium

    CVE-2019-9816

    Last Modified: 29 May 2019

    A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

    Source:Google Security Research
    Published:22 May 2019
    8.8
    High

    CVE-2019-9813

    Last Modified: 3 Apr 2019

    Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

    Source:Google Security Research
    Published:22 Mar 2019
    8.8
    High

    CVE-2019-9810

    Last Modified: 26 Mar 2019

    Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

    Source:xuechiyaobai
    Published:22 Mar 2019
    9.8
    Critical

    CVE-2019-9792

    Last Modified: 29 May 2019

    The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Source:Google Security Research
    Published:20 Mar 2019
    9.8
    Critical

    CVE-2019-9791

    Last Modified: 26 Mar 2019

    The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Source:Google Security Research
    Published:20 Mar 2019
    8.8
    High

    CVE-2019-9787

    Last Modified: 21 Nov 2024

    WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.

    Published:14 Mar 2019
    8.8
    High

    CVE-2019-9769

    Last Modified: 14 Mar 2019

    PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.

    Source:Gionathan Reale
    Published:14 Mar 2019
    7.5
    High

    CVE-2019-9768

    Last Modified: 3 Apr 2019

    Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token.

    Source:Benjamin Zink Loft_ Gionathan Reale
    Published:14 Mar 2019
    7.8
    High

    CVE-2019-9767

    Last Modified: 14 Mar 2019

    Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wma file.

    Source:Gionathan Reale
    Published:14 Mar 2019
    7.8
    High

    CVE-2019-9766

    Last Modified: 14 Mar 2019

    Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .mp3 file.

    Source:Gionathan Reale
    Published:14 Mar 2019
    9.8
    Critical

    CVE-2019-9760

    Last Modified: 14 Mar 2019

    FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-controlled machine that sends crafted responses. Long responses can also crash the FTP client with memory corruption.

    Source:w4fz5uck5
    Published:14 Mar 2019
    7.8
    High

    CVE-2019-9745

    Last Modified: 21 Nov 2024

    CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used to import data from CRM software using plugins (.dll files). The plugin to import data from the EXQUISE software (DatasourceExquiseExporter.dll) can be persuaded to start arbitrary programs (including batch files) that are executed using the same privileges as Recognition Update Client Service (NT AUTHORITY\SYSTEM), thus elevating privileges. This occurs because a higher-privileged process executes scripts from a directory writable by a lower-privileged user.

    Published:14 Oct 2019
    8.8
    High

    CVE-2019-9730

    Last Modified: 21 Nov 2024

    Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an unpublished API.

    Published:5 Jun 2019
    7.8
    High

    CVE-2019-9729

    Last Modified: 21 Nov 2024

    In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

    Published:12 Mar 2019
    7.8
    High

    CVE-2019-9702

    Last Modified: 21 Nov 2024

    Symantec Endpoint Encryption, prior to SEE 11.3.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

    Published:1 Jul 2019
    4.8
    Medium

    CVE-2019-9701

    Last Modified: 3 Jul 2019

    DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.

    Source:Chapman Schleiss
    Published:19 Jun 2019
    6.5
    Medium

    CVE-2019-9692

    Last Modified: 28 Mar 2019

    class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard image file extension (GIF, JPG, JPEG, or PNG).

    Source:Metasploit
    Published:11 Mar 2019
    8.8
    High

    CVE-2019-9673

    Last Modified: 21 Nov 2024

    Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

    Published:5 Jun 2019
    9.8
    Critical

    CVE-2019-9670

    Last Modified: 12 Apr 2019

    mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.

    Source:Metasploit
    Published:29 May 2019
    9.8
    Critical

    CVE-2019-9653

    Last Modified: 21 Nov 2024

    NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.

    Published:31 May 2019
    6.1
    Medium

    CVE-2019-9650

    Last Modified: 21 Mar 2019

    An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.

    Source:0xB9
    Published:11 Mar 2019
    5.3
    Medium

    CVE-2019-9649

    Last Modified: 13 Mar 2019

    An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.

    Source:Kevin Randall
    Published:22 Mar 2019
    5.3
    Medium

    CVE-2019-9648

    Last Modified: 30 Apr 2019

    An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.

    Source:Kevin Randall
    Published:22 Mar 2019
    6.1
    Medium

    CVE-2019-9647

    Last Modified: 19 Mar 2019

    Gila CMS 1.9.1 has XSS.

    Source:Ahmet Ümit BAYRAM
    Published:5 Jun 2019
    8.8
    High

    CVE-2019-9625

    Last Modified: 8 Mar 2019

    JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.

    Source:ManhNho
    Published:7 Mar 2019
    7.8
    High

    CVE-2019-9624

    Last Modified: 8 Mar 2019

    Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Download" privileges to upload a crafted .cgi file via the /updown/upload.cgi URI.

    Source:AkkuS
    Published:7 Mar 2019
    9.8
    Critical

    CVE-2019-9623

    Last Modified: 8 Mar 2019

    Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

    Source:AkkuS
    Published:7 Mar 2019
    4.3
    Medium

    CVE-2019-9622

    Last Modified: 8 Mar 2019

    eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file.

    Source:AkkuS
    Published:7 Mar 2019
    7.5
    High

    CVE-2019-9621

    Last Modified: 5 Jun 2019

    Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.

    Source:k8gege
    Published:30 Apr 2019
    9.8
    Critical

    CVE-2019-9618

    Last Modified: 13 Mar 2019

    The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.

    Source:Manuel García Cárdenas
    Published:13 May 2019
    7.5
    High

    CVE-2019-9601

    Last Modified: 7 Mar 2019

    The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many simultaneous /?Key=PhoneRequestAuthorization requests.

    Source:s4vitar
    Published:6 Mar 2019
    7.5
    High

    CVE-2019-9600

    Last Modified: 7 Mar 2019

    The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets.

    Source:s4vitar
    Published:6 Mar 2019
    7.5
    High

    CVE-2019-9599

    Last Modified: 7 Mar 2019

    The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.

    Source:s4vitar
    Published:6 Mar 2019
    6.5
    Medium

    CVE-2019-9596

    Last Modified: 21 Nov 2024

    Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.

    Published:23 Oct 2019
    6.1
    Medium

    CVE-2019-9593

    Last Modified: 8 Apr 2019

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Ramikan
    Published:6 Mar 2019
    6.1
    Medium

    CVE-2019-9592

    Last Modified: 8 Apr 2019

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:Ramikan
    Published:6 Mar 2019
    6.1
    Medium

    CVE-2019-9591

    Last Modified: 8 Apr 2019

    A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web script or HTML via the brandUrl parameter.

    Source:Ramikan
    Published:6 Mar 2019
    8.8
    High

    CVE-2019-9581

    Last Modified: 6 Mar 2019

    phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.

    Source:AkkuS
    Published:6 Mar 2019
    6.1
    Medium

    CVE-2019-9580

    Last Modified: 21 Nov 2024

    In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.

    Published:9 Mar 2019
    5.4
    Medium

    CVE-2019-9556

    Last Modified: 4 Mar 2019

    FiberHome an5506-04-f RP2669 devices have XSS.

    Source:Tauco
    Published:31 Dec 2019
    6.1
    Medium

    CVE-2019-9554

    Last Modified: 4 Mar 2019

    In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

    Source:Ismail Tasdelen
    Published:31 Dec 2019
    6.1
    Medium

    CVE-2019-9553

    Last Modified: 4 Mar 2019

    Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

    Source:Ismail Tasdelen
    Published:31 Dec 2019
    7.5
    High

    CVE-2019-9511

    Last Modified: 14 Jan 2025

    Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

    Published:13 Aug 2019