9.8
    Critical

    CVE-2019-8016

    Last Modified: 15 Aug 2019

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Source:Google Security Research
    Published:20 Aug 2019
    8.8
    High

    CVE-2019-8014

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published:20 Aug 2019
    9.8
    Critical

    CVE-2019-7839

    Last Modified: 21 Nov 2024

    ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published:12 Jun 2019
    7.5
    High

    CVE-2019-7751

    Last Modified: 4 Mar 2019

    A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for privilege escalation by dumping the local machine's SAM and SYSTEM database files, and possibly remote code execution.

    Source:0v3rride
    Published:31 Dec 2019
    7.5
    High

    CVE-2019-7711

    Last Modified: 21 Nov 2024

    An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented shell command "prompt" sets the (user controlled) shell's prompt value, which is used as a format string input to printf, resulting in an information leak of memory addresses.

    Published:26 Mar 2019
    9
    Critical

    CVE-2019-7671

    Last Modified: 12 Nov 2019

    Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.

    Source:LiquidWorm
    Published:5 Jun 2019
    7.2
    High

    CVE-2019-7670

    Last Modified: 12 Nov 2019

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system.

    Source:LiquidWorm
    Published:1 Jul 2019
    8.8
    High

    CVE-2019-7666

    Last Modified: 12 Nov 2019

    Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password, which may allow an attacker with access to the database to login as admin without decrypting the password.

    Source:LiquidWorm
    Published:1 Jul 2019
    7.7
    High

    CVE-2019-7652

    Last Modified: 13 May 2019

    TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type, and provide an SSRF payload like "http://127.0.0.1:22" in the Data parameter. The result can be seen in the main dashboard. Thus, it is possible to do port scans on localhost and intranet hosts.

    Source:Alexandre Basquin
    Published:9 May 2019
    4.8
    Medium

    CVE-2019-7646

    Last Modified: 11 Feb 2019

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.

    Source:DKM
    Published:26 Mar 2019
    7.5
    High

    CVE-2019-7642

    Last Modified: 21 Nov 2024

    D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).

    Published:25 Mar 2019
    4.9
    Medium

    CVE-2019-7616

    Last Modified: 21 Nov 2024

    Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

    Published:30 Jul 2019
    9.8
    Critical

    CVE-2019-7609

    Last Modified: 7 Nov 2025

    Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

    Published:19 Feb 2019
    6.1
    Medium

    CVE-2019-7541

    Last Modified: 13 Feb 2019

    Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.

    Source:Mehmet EMIROGLU
    Published:7 May 2019
    9.8
    Critical

    CVE-2019-7489

    Last Modified: 21 Nov 2024

    A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

    Published:23 Dec 2019
    9.8
    Critical

    CVE-2019-7482

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

    Published:19 Dec 2019
    9.8
    Critical

    CVE-2019-7442

    Last Modified: 13 May 2019

    An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

    Source:Marcelo Toran
    Published:8 May 2019
    6.5
    Medium

    CVE-2019-7441

    Last Modified: 2 Apr 2019

    cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state

    Source:Vikas Chaudhary
    Published:20 Mar 2019
    6.5
    Medium

    CVE-2019-7440

    Last Modified: 2 Apr 2019

    JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).

    Source:Vikas Chaudhary
    Published:20 Mar 2019
    6.5
    Medium

    CVE-2019-7439

    Last Modified: 25 Apr 2019

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.

    Source:Vikas Chaudhary
    Published:20 Mar 2019
    6.1
    Medium

    CVE-2019-7438

    Last Modified: 25 Apr 2019

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.

    Source:Vikas Chaudhary
    Published:20 Mar 2019
    Unknown

    CVE-2019-7406

    https://github.com/Alonzozzz/alonzzzo

    6.1
    Medium

    CVE-2019-7400

    Last Modified: 26 Mar 2019

    Rukovoditel before 2.4.1 allows XSS.

    Source:Javier Olmedo
    Published:5 Feb 2019
    8.8
    High

    CVE-2019-7391

    Last Modified: 5 Feb 2019

    ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

    Source:Yusuf Furkan
    Published:17 Mar 2019
    7.8
    High

    CVE-2019-7385

    Last Modified: 4 Mar 2019

    An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON products with the firmware version ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 or below, The values of the newpass and confpass parameters in /bin/WebMGR are used in a system call in the firmware. Because there is no user input validation, this leads to authenticated code execution on the device.

    Source:JameelNabbo
    Published:17 Mar 2019
    8.8
    High

    CVE-2019-7357

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

    Published:10 Nov 2020
    5.4
    Medium

    CVE-2019-7356

    Last Modified: 21 Nov 2024

    Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.

    Published:4 Nov 2020
    9.8
    Critical

    CVE-2019-7304

    Last Modified: 13 Feb 2019

    Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37.1.

    Source:Chris Moberly
    Published:23 Apr 2019
    7.5
    High

    CVE-2019-7303

    Last Modified: 22 Mar 2019

    A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.

    Source:Google Security Research
    Published:23 Apr 2019
    7.8
    High

    CVE-2019-7286

    Last Modified: 6 May 2019

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges.

    Source:ZecOps
    Published:18 Dec 2019
    9.8
    Critical

    CVE-2019-7276

    Last Modified: 12 Nov 2019

    Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

    Source:LiquidWorm
    Published:1 Jul 2019
    9.8
    Critical

    CVE-2019-7274

    Last Modified: 12 Nov 2019

    Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.

    Source:LiquidWorm
    Published:1 Jul 2019
    8.8
    High

    CVE-2019-7273

    Last Modified: 12 Nov 2019

    Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

    Source:LiquidWorm
    Published:1 Jul 2019
    5.3
    Medium

    CVE-2019-7272

    Last Modified: 12 Nov 2019

    Optergy Proton/Enterprise devices allow Username Disclosure.

    Source:LiquidWorm
    Published:1 Jul 2019
    9.8
    Critical

    CVE-2019-7269

    Last Modified: 12 Nov 2019

    Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.

    Source:LiquidWorm
    Published:2 Jul 2019
    9.8
    Critical

    CVE-2019-7265

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).

    Source:LiquidWorm
    Published:2 Jul 2019
    8.8
    High

    CVE-2019-7262

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

    Source:LiquidWorm
    Published:2 Jul 2019
    10
    Critical

    CVE-2019-7257

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow Unrestricted File Upload.

    Source:LiquidWorm
    Published:2 Jul 2019
    9.8
    Critical

    CVE-2019-7256

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow Command Injections.

    Source:LiquidWorm
    Published:2 Jul 2019
    6.1
    Medium

    CVE-2019-7255

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow XSS.

    Source:LiquidWorm
    Published:2 Jul 2019
    7.5
    High

    CVE-2019-7254

    Last Modified: 12 Nov 2019

    Linear eMerge E3-Series devices allow File Inclusion.

    Source:LiquidWorm
    Published:2 Jul 2019
    9.8
    Critical

    CVE-2019-7238

    Last Modified: 6 Nov 2025

    Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

    Published:21 Mar 2019
    6.1
    Medium

    CVE-2019-7219

    Last Modified: 21 Nov 2024

    Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

    Published:11 Apr 2019
    7.8
    High

    CVE-2019-7216

    Last Modified: 21 Nov 2024

    An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user to upload any type of file by using % characters within the extension, e.g., file.%ph%p becomes file.php.

    Published:31 Jan 2019
    9.8
    Critical

    CVE-2019-7214

    Last Modified: 9 Dec 2020

    SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

    Source:1F98D
    Published:24 Apr 2019
    6.5
    Medium

    CVE-2019-7213

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by putting files inside the web directories.

    Published:24 Apr 2019
    9.8
    Critical

    CVE-2019-7192

    Last Modified: 27 Oct 2025

    This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

    Published:5 Dec 2019
    7.5
    High

    CVE-2019-7181

    Last Modified: 22 Apr 2019

    Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.

    Source:Dino Covotsos
    Published:9 May 2019
    9.8
    Critical

    CVE-2019-7164

    Last Modified: 21 Nov 2024

    SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

    Published:1 Feb 2019
    9.8
    Critical

    CVE-2019-7139

    Last Modified: 21 Nov 2024

    An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.

    Published:10 Apr 2019