Total
34640 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-15355 | 1 Tecno-mobile | 2 Camon Iclick, Camon Iclick Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15354 | 1 Ulefone | 2 Armor 5, Armor 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Ulefone Armor 5 Android device with a build fingerprint of Ulefone/Ulefone_Armor_5/Ulefone_Armor_5:8.1.0/O11019/1528806701:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15353 | 1 Coolpad | 2 N3c, N3c Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Coolpad N3C Android device with a build fingerprint of Coolpad/N3C/N3C:8.1.0/O11019/1538236809:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15352 | 1 Coolpad | 2 Mega 5, Mega 5 Firmware | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
|
|||||
| CVE-2019-15344 | 1 Tecno-mobile | 2 Camon Iclick, Camon Iclick Firmware | 2024-11-21 | 9.3 HIGH | 8.1 HIGH |
|
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the atta ...
Show More |
|||||
| CVE-2019-15330 | 1 Webp Express Project | 1 Webp Express | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
|
|||||
| CVE-2019-15325 | 1 Galliumos | 1 Galliumos | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/ptrace_scope to 1, which might increase risk because of the appearance that a protection mechanism is present when actually it is not.
|
|||||
| CVE-2019-15322 | 1 Wpmadeasy | 1 Shortcode Factory | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
|
|||||
| CVE-2019-15312 | 1 Linkplay | 1 Linkplay | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
|
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.
|
|||||
| CVE-2019-15293 | 1 Acdsee | 1 Photo Studio | 2024-11-21 | 4.6 MEDIUM | 7.8 HIGH |
|
An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.
|
|||||
| CVE-2019-15237 | 2 Fedoraproject, Roundcube | 2 Fedora, Webmail | 2024-11-21 | 4.3 MEDIUM | 7.4 HIGH |
|
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
|
|||||
| CVE-2019-15137 | 1 Eprosima | 1 Fast-rtps | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
The Access Control plugin in eProsima Fast RTPS through 1.9.0 allows fnmatch pattern matches with topic name strings (instead of the permission expressions themselves), which can lead to unintended connections between participants in a Data Distribution Service (DDS) network.
|
|||||
| CVE-2019-15111 | 1 Wp Front End Profile Project | 1 Wp Front End Profile | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.
|
|||||
| CVE-2019-15088 | 1 Prise | 1 Adas | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.
|
|||||
| CVE-2019-15080 | 1 Morph Project | 1 Morph | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo in the constructor of the Owned contract (which is inherited by MORPH Token) allows attackers to acquire contract ownership. A new owner can subsequently obtain MORPH Tokens for free and can perform a DoS attack.
|
|||||
| CVE-2019-15079 | 1 Eai Project | 1 Eai | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This vulnerability could be used by an attacker to acquire EAI tokens for free.
|
|||||
| CVE-2019-15078 | 1 Xbornid | 1 Xbornid | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that allows an attacker to change the owner of the contract and obtain cryptocurrency for free.
|
|||||
| CVE-2019-15069 | 1 Gigastone | 2 Smart Battery A4, Smart Battery A4 Firmware | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 . An attacker can bypass authentication without modifying device file and gain web page management privilege.
|
|||||
| CVE-2019-15067 | 1 Gigastone | 2 Smart Battery A2-25de, Smart Battery A2-25de Firmware | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
|
An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware version ?<= SECFS-2013-10-16-13:42:58-629c30ee-60c68be6. An attacker can bypass authentication and gain privilege by modifying the login page.
|
|||||
| CVE-2019-15066 | 1 Hinet | 2 Gpon, Gpon Firmware | 2024-11-21 | 10.0 HIGH | 10.0 CRITICAL |
|
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 6998. CVSS 3.0 Base score 10.0. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
|
|||||
| CVE-2019-15065 | 1 Hinet | 2 Gpon, Gpon Firmware | 2024-11-21 | 5.0 MEDIUM | 9.3 CRITICAL |
|
A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
|
|||||
| CVE-2019-15038 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.
|
|||||
| CVE-2019-15035 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
|
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
|
|||||
| CVE-2019-15028 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
|
|||||
| CVE-2019-15009 | 1 Atlassian | 2 Crucible, Fisheye | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
|
|||||
| CVE-2019-14986 | 1 Eq-3 | 4 Homematic Ccu2, Homematic Ccu2 Firmware, Homematic Ccu3 and 1 more | 2024-11-21 | 9.3 HIGH | 8.1 HIGH |
|
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password") are exposed.
|
|||||
| CVE-2019-14940 | 1 Spdk | 1 Storage Performance Development Kit | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
|
In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input.
|
|||||
| CVE-2019-14939 | 1 Mysql Project | 1 Mysql | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.
|
|||||
| CVE-2019-14936 | 1 Easyappointments | 1 Easy\!appointments | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
|
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
|
|||||
| CVE-2019-14920 | 1 Billion | 2 Sg600 R2, Sg600 R2 Firmware | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
|
Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an authenticated attacker to gain root execution privileges over the device via a hidden etc_ro/web/adm/system_command.asp shell feature.
|
|||||
| CVE-2019-14902 | 4 Canonical, Debian, Opensuse and 1 more | 4 Ubuntu Linux, Debian Linux, Leap and 1 more | 2024-11-21 | 5.5 MEDIUM | 5.4 MEDIUM |
|
There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not automatically be taken away on all domain controllers.
|
|||||
| CVE-2019-14888 | 2 Netapp, Redhat | 6 Active Iq Unified Manager, Jboss Data Grid, Jboss Enterprise Application Platform and 3 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
|
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
|
|||||
| CVE-2019-14880 | 1 Moodle | 1 Moodle | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
|
A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.
|
|||||
| CVE-2019-14820 | 1 Redhat | 4 Jboss Enterprise Application Platform, Jboss Fuse, Keycloak and 1 more | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
|
|||||
| CVE-2019-14809 | 2 Debian, Golang | 2 Debian Linux, Go | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number. For example, an attacker can compose a crafted javascript:// URL that results in a hostname of google.com.
|
|||||
| CVE-2019-14783 | 1 Google | 1 Android | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
|
On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764.
|
|||||
| CVE-2019-14773 | 1 Webcraftic | 1 Woody Ad Snippets | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
|
admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion.
|
|||||
| CVE-2019-14765 | 1 Dimo-crm | 1 Yellowbox Crm | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
|
Incorrect Access Control in AfficheExplorateurParam() in DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to use administrative controllers.
|
|||||
| CVE-2019-14730 | 1 Control-webpanel | 1 Webpanel | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a domain from a victim's account via an attacker account.
|
|||||
| CVE-2019-14729 | 1 Control-webpanel | 1 Webpanel | 2024-11-21 | 5.5 MEDIUM | 4.3 MEDIUM |
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a sub-domain from a victim's account via an attacker account.
|
|||||