8.8
    High

    CVE-2019-7069

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published:24 May 2019
    5.4
    Medium

    CVE-2019-7004

    Last Modified: 24 Feb 2020

    A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.

    Source:Scott Goodwin
    Published:11 Dec 2019
    8.8
    High

    CVE-2019-6989

    Last Modified: 9 Apr 2019

    TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.

    Source:Grzegorz Wypych
    Published:6 Jun 2019
    6.1
    Medium

    CVE-2019-6979

    Last Modified: 28 Jan 2019

    An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.

    Source:0xB9
    Published:28 Jan 2019
    8.8
    High

    CVE-2019-6977

    Last Modified: 9 Apr 2019

    gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

    Source:cfreal
    Published:9 Dec 2018
    8.1
    High

    CVE-2019-6974

    Last Modified: 15 Feb 2019

    In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

    Source:Google Security Research
    Published:7 Feb 2019
    7.5
    High

    CVE-2019-6973

    Last Modified: 28 Jan 2019

    Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.

    Source:Andrew Watson
    Published:17 Mar 2019
    9.8
    Critical

    CVE-2019-6971

    Last Modified: 10 Oct 2019

    An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.

    Source:Uriel Kosayev
    Published:19 Jun 2019
    8.8
    High

    CVE-2019-6967

    Last Modified: 28 Jan 2019

    AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.

    Source:Ali Can Gönüllü
    Published:17 Mar 2019
    6.1
    Medium

    CVE-2019-6965

    Last Modified: 28 Mar 2019

    An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.

    Source:BlackFog Team
    Published:18 Jun 2019
    9.8
    Critical

    CVE-2019-6814

    Last Modified: 29 Jul 2019

    A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.

    Source:Metasploit
    Published:22 May 2019
    6.1
    Medium

    CVE-2019-6804

    Last Modified: 28 Jan 2019

    An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.

    Source:Ishaq Mohammed
    Published:25 Jan 2019
    6.1
    Medium

    CVE-2019-6780

    Last Modified: 25 Jan 2019

    The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.

    Source:MTK
    Published:24 Jan 2019
    9.4
    Critical

    CVE-2019-6716

    Last Modified: 16 Mar 2019

    An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.

    Source:0v3rride
    Published:17 Mar 2019
    7.5
    High

    CVE-2019-6715

    Last Modified: 21 Nov 2024

    pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.

    Published:1 Apr 2019
    9.8
    Critical

    CVE-2019-6714

    Last Modified: 12 Feb 2019

    An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.

    Source:Dustin Cobb
    Published:17 Mar 2019
    8.8
    High

    CVE-2019-6710

    Last Modified: 6 May 2019

    Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.

    Source:Ali Can Gönüllü
    Published:7 Mar 2019
    7.5
    High

    CVE-2019-6706

    Last Modified: 25 Jan 2019

    Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

    Source:Fady Mohammed Osman
    Published:10 Jan 2019
    6.5
    Medium

    CVE-2019-6693

    Last Modified: 24 Oct 2025

    Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

    Published:21 Nov 2019
    7.5
    High

    CVE-2019-6690

    Last Modified: 21 Nov 2024

    python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perform the attack, the passphrase to gnupg must be controlled by the adversary and the ciphertext should be trusted. Related to a "CWE-20: Improper Input Validation" issue affecting the affect functionality component.

    Published:23 Jan 2019
    4.7
    Medium

    CVE-2019-6588

    Last Modified: 11 Jun 2019

    In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.

    Source:Valerio Brussani
    Published:3 Jun 2019
    7.5
    High

    CVE-2019-6545

    Last Modified: 12 Feb 2019

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine.

    Source:Jacob Baines
    Published:13 Feb 2019
    9.8
    Critical

    CVE-2019-6543

    Last Modified: 12 Feb 2019

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.

    Source:Jacob Baines
    Published:13 Feb 2019
    8.8
    High

    CVE-2019-6498

    Last Modified: 22 Jan 2019

    GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.

    Source:Dhiraj Mishra
    Published:21 Jan 2019
    8.8
    High

    CVE-2019-6487

    Last Modified: 21 Nov 2024

    TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.

    Published:18 Jan 2019
    7.5
    High

    CVE-2019-6467

    Last Modified: 21 Nov 2024

    A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that is served locally. The most likely scenario where this might occur is if the server, in addition to performing NXDOMAIN redirection for recursive clients, is also serving a local copy of the root zone or using mirroring to provide the root zone, although other configurations are also possible. Versions affected: BIND 9.12.0-> 9.12.4, 9.14.0. Also affects all releases in the 9.13 development branch.

    Published:24 Apr 2019
    8.1
    High

    CVE-2019-6453

    Last Modified: 20 Feb 2019

    mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable).

    Source:ProofOfCalc
    Published:18 Feb 2019
    8.1
    High

    CVE-2019-6447

    Last Modified: 29 Jun 2021

    The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

    Source:Nehal Zaman
    Published:16 Jan 2019
    9.8
    Critical

    CVE-2019-6446

    Last Modified: 21 Jul 2025

    An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

    Published:16 Jan 2019
    6.5
    Medium

    CVE-2019-6445

    Last Modified: 17 Mar 2019

    An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.

    Source:Magnus Klaaborg Stubman
    Published:16 Jan 2019
    9.1
    Critical

    CVE-2019-6444

    Last Modified: 16 Jan 2019

    An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.

    Source:Magnus Klaaborg Stubman
    Published:16 Jan 2019
    9.1
    Critical

    CVE-2019-6443

    Last Modified: 16 Jan 2019

    An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.

    Source:Magnus Klaaborg Stubman
    Published:16 Jan 2019
    6.5
    Medium

    CVE-2019-6442

    Last Modified: 17 Mar 2019

    An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

    Source:Magnus Klaaborg Stubman
    Published:16 Jan 2019
    9.8
    Critical

    CVE-2019-6441

    Last Modified: 16 Jan 2019

    An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.

    Source:Adithyan AK
    Published:19 Mar 2019
    9.8
    Critical

    CVE-2019-6440

    Last Modified: 21 Nov 2024

    Zemana AntiMalware before 3.0.658 Beta mishandles update logic.

    Published:16 Jan 2019
    8.1
    High

    CVE-2019-6340

    Last Modified: 7 Mar 2019

    Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

    Source:Metasploit
    Published:21 Feb 2019
    9.8
    Critical

    CVE-2019-6339

    Last Modified: 21 Nov 2024

    In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

    Published:22 Jan 2019
    7.8
    High

    CVE-2019-6329

    Last Modified: 21 Nov 2024

    HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.

    Published:25 Jun 2019
    8.8
    High

    CVE-2019-6282

    Last Modified: 20 Mar 2019

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

    Source:Kumar Saurav
    Published:19 Mar 2019
    8.8
    High

    CVE-2019-6279

    Last Modified: 20 Mar 2019

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

    Source:Kumar Saurav
    Published:19 Mar 2019
    8.8
    High

    CVE-2019-6275

    Last Modified: 17 Mar 2019

    Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

    Source:Pasquale Turi
    Published:19 Mar 2019
    8.8
    High

    CVE-2019-6274

    Last Modified: 17 Mar 2019

    Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.

    Source:Pasquale Turi
    Published:19 Mar 2019
    6.5
    Medium

    CVE-2019-6273

    Last Modified: 17 Mar 2019

    download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.

    Source:Pasquale Turi
    Published:19 Mar 2019
    8.8
    High

    CVE-2019-6272

    Last Modified: 17 Mar 2019

    Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

    Source:Pasquale Turi
    Published:19 Mar 2019
    4.8
    Medium

    CVE-2019-6263

    Last Modified: 18 Jan 2019

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.

    Source:Praveen Sutar
    Published:16 Jan 2019
    9.8
    Critical

    CVE-2019-6260

    Last Modified: 21 Nov 2024

    The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.

    Published:22 Jan 2019
    8.8
    High

    CVE-2019-6250

    Last Modified: 21 Nov 2024

    A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of bytes beyond the bounds of a buffer, which can be leveraged to run arbitrary code on the target system. The memory layout allows the attacker to inject OS commands into a data structure located immediately after the problematic buffer (i.e., it is not necessary to use a typical buffer-overflow exploitation technique that changes the flow of control).

    Published:8 Jan 2019
    8.8
    High

    CVE-2019-6249

    Last Modified: 14 Jan 2019

    An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.

    Source:AllenChen
    Published:13 Jan 2019
    7.8
    High

    CVE-2019-6225

    Last Modified: 25 Jan 2019

    A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.

    Source:Google Security Research
    Published:5 Mar 2019
    8.8
    High

    CVE-2019-6224

    Last Modified: 20 Feb 2019

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.

    Source:Google Security Research
    Published:5 Mar 2019