Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-16273 | 1 Dten | 4 D5, D5 Firmware, D7 and 1 more | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.
|
|||||
| CVE-2019-16257 | 1 Motorola | 2 Motorola, Motorola Firmware | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
|
|||||
| CVE-2019-16253 | 1 Samsung | 1 Text-to-speech | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate privileges, e.g., to system privileges. The Samsung case ID is 101755.
|
|||||
| CVE-2019-16251 | 1 Yithemes | 38 Yith Advanced Refund System For Woocommerce, Yith Color And Label Variations For Woocommerce, Yith Custom Thank You Page For Woocommerce and 35 more | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
|
|||||
| CVE-2019-16248 | 1 Telegram | 1 Telegram | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a potentially misleading UI indication that a sender can remove a recipient's copy of a previously sent image (analogous to supported functionality in which a sender can remove a recipient's copy of a previously sent message).
|
|||||
| CVE-2019-16247 | 1 Deltaww | 1 Dcisoft | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
Delta DCISoft 1.21 has a User Mode Write AV starting at CommLib!CCommLib::SetSerializeData+0x000000000000001b.
|
|||||
| CVE-2019-16245 | 1 Openmicroscopy | 1 Omero | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
OMERO before 5.6.1 makes the details of each user available to all users.
|
|||||
| CVE-2019-16244 | 1 Openmicroscopy | 1 Omero.server | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
|
|||||
| CVE-2019-16214 | 1 Libra | 1 Libra Core | 2024-11-21 | 3.5 LOW | 5.7 MEDIUM |
|
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character for a comment. For example, a Move module author can enter the // sequence (which introduces a single-line comment), followed by very brief comment text, the \r character, and code that has security-critical functionality. In many popular environments, this code is displayed on a separate line, and th ...
Show More |
|||||
| CVE-2019-16181 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 4.0 MEDIUM | 2.7 LOW |
|
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.
|
|||||
| CVE-2019-16180 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
|
|||||
| CVE-2019-16176 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the path to the application in the filesystem.
|
|||||
| CVE-2019-16170 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.5 MEDIUM | 7.1 HIGH |
|
An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.
|
|||||
| CVE-2019-16155 | 1 Fortinet | 1 Forticlient | 2024-11-21 | 6.6 MEDIUM | 7.1 HIGH |
|
A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched process. Further more, FortiClient for Linux 6.2.2 and below allow low privilege user write the system backup file under root privilege through GUI thus can cause root system file overwrite.
|
|||||
| CVE-2019-16110 | 1 Blade-group | 1 Shadow | 2024-11-21 | 6.8 MEDIUM | 8.1 HIGH |
|
The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream.
|
|||||
| CVE-2019-16109 | 1 Plataformatec | 1 Devise | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)
|
|||||
| CVE-2019-16103 | 1 Silver-peak | 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware | 2024-11-21 | 9.0 HIGH | 7.2 HIGH |
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
|
|||||
| CVE-2019-16100 | 1 Silver-peak | 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.
|
|||||
| CVE-2019-16060 | 1 Airbrake | 1 Airbrake Ruby | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
|
The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).
|
|||||
| CVE-2019-16056 | 7 Canonical, Debian, Fedoraproject and 4 more | 10 Ubuntu Linux, Debian Linux, Fedora and 7 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.
|
|||||
| CVE-2019-16023 | 1 Cisco | 20 Asr 9000, Asr 9010, Asr 9904 and 17 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A suc ...
Show More |
|||||
| CVE-2019-16021 | 1 Cisco | 20 Asr 9000, Asr 9010, Asr 9904 and 17 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A suc ...
Show More |
|||||
| CVE-2019-16019 | 1 Cisco | 20 Asr 9000, Asr 9010, Asr 9904 and 17 more | 2024-11-21 | 5.0 MEDIUM | 8.6 HIGH |
|
Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attacker could exploit these vulnerabilities by sending BGP EVPN update messages with malformed attributes to be processed by an affected system. A suc ...
Show More |
|||||
| CVE-2019-15963 | 1 Cisco | 1 Unified Communications Manager | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the web-based management interface of the affected service. An attacker could exploit this vulnerability by accessing the interface and viewing restricted portions of the software configur ...
Show More |
|||||
| CVE-2019-15893 | 1 Sonatype | 1 Nexus Repository Manager | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
|
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
|
|||||
| CVE-2019-15863 | 1 Convertplug | 1 Convertplus | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants.
|
|||||
| CVE-2019-15854 | 1 Maarch | 1 Maarch Rm | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration privileges via a crafted PUT request to an unauthorized resource.
|
|||||
| CVE-2019-15846 | 2 Debian, Exim | 2 Debian Linux, Exim | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
|
|||||
| CVE-2019-15845 | 2 Canonical, Ruby-lang | 2 Ubuntu Linux, Ruby | 2024-11-21 | 6.4 MEDIUM | 6.5 MEDIUM |
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
|
|||||
| CVE-2019-15826 | 1 Wpserveur | 1 Wps Hide Login | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
|
|||||
| CVE-2019-15825 | 1 Wpserveur | 1 Wps Hide Login | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
|
|||||
| CVE-2019-15824 | 1 Wpserveur | 1 Wps Hide Login | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
|
|||||
| CVE-2019-15823 | 1 Wpserveur | 1 Wps Hide Login | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
|
|||||
| CVE-2019-15821 | 1 Bold-themes | 1 Bold Page Builder | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.
|
|||||
| CVE-2019-15804 | 1 Zyxel | 18 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 15 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process, undocumented functionality is triggered. Specifically, a menu can be triggered by sending the SIGQUIT signal to the CLI application (e.g., through CTRL+\ via SSH). The access control check for this menu does work and prohibits accessing the menu, which contains "Password recovery for specific user" options. The menu is believed to be accessible using a serial console.
|
|||||
| CVE-2019-15789 | 1 Canonical | 1 Microk8s | 2024-11-21 | 7.2 HIGH | 8.8 HIGH |
|
Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.
|
|||||
| CVE-2019-15742 | 1 Plantronics | 1 Plantronics Hub | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
|
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker can exploit this issue to gain elevated privileges.
|
|||||
| CVE-2019-15741 | 1 Gitlab | 1 Omnibus | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
|
|||||
| CVE-2019-15737 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 6.4 MEDIUM | 6.5 MEDIUM |
|
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.
|
|||||
| CVE-2019-15732 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.
|
|||||