CVE-2019-19000 to CVE-2019-19999
196 CVEs with public proof-of-concept exploits.
- CVE-2019-190111 PoCMiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.
- CVE-2019-190123 PoCsAn integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in…
- CVE-2019-190131 PoCA CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
- CVE-2019-190141 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast number…
- CVE-2019-190151 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to…
- CVE-2019-190161 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration interface are…
- CVE-2019-190171 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker…
- CVE-2019-190181 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web…
- CVE-2019-190191 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an attacker can execute…
- CVE-2019-190201 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup…
- CVE-2019-190211 PoCAn issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web…
- CVE-2019-190301 PoCCloud Native Computing Foundation Harbor before 1.10.3 and 2.x before 2.0.1 allows resource enumeration because unauthenticated API calls…
- CVE-2019-190312 PoCsEasy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming…
- CVE-2019-190322 PoCsXMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is…
- CVE-2019-190331 PoCJalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor…
- CVE-2019-190342 PoCsZoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically…
- CVE-2019-190351 PoCjhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and…
- CVE-2019-190361 PoCbtrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because…
- CVE-2019-190371 PoCext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because…
- CVE-2019-190391 PoC__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which…
- CVE-2019-191131 PoCmain/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL…
- CVE-2019-191332 PoCsThe CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it…
- CVE-2019-191341 PoCThe Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter…
- CVE-2019-191423 PoCsIntelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmware.cfg URI.
- CVE-2019-191434 PoCsTP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.
- CVE-2019-191911 PoCShibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service…
- CVE-2019-191941 PoCThe Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for…
- CVE-2019-191971 PoCIOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation,…
- CVE-2019-191981 PoCThe Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.
- CVE-2019-192001 PoCREDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
- CVE-2019-192032 PoCsAn issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is…
- CVE-2019-192042 PoCsAn issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as…
- CVE-2019-192084 PoCsCodiad Web IDE through 2.8.4 allows PHP Code injection.
- CVE-2019-192091 PoCDolibarr ERP/CRM before 10.0.3 allows SQL Injection.
- CVE-2019-192101 PoCDolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
- CVE-2019-192111 PoCDolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
- CVE-2019-192121 PoCDolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
- CVE-2019-192211 PoCIn Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or…
- CVE-2019-192221 PoCA Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject…
- CVE-2019-192231 PoCA Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot…
- CVE-2019-192241 PoCA Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to…
- CVE-2019-192251 PoCA Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change…
- CVE-2019-192261 PoCA Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable…
- CVE-2019-192283 PoCsFronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today…
- CVE-2019-192293 PoCsadmincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
- CVE-2019-192311 PoCAn insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local…
- CVE-2019-192411 PoCIn the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka…
- CVE-2019-192453 PoCsNAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when…
- CVE-2019-192652 PoCsIceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
- CVE-2019-192662 PoCsIceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
- CVE-2019-193061 PoCThe Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
- CVE-2019-193151 PoCNLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the…
- CVE-2019-193181 PoCIn the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in…
- CVE-2019-193191 PoCIn the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access…
- CVE-2019-193563 PoCsKEVNetis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability…
- CVE-2019-193634 PoCsAn issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege…
- CVE-2019-193661 PoCA cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject…
- CVE-2019-193671 PoCA cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web…
- CVE-2019-193683 PoCsA Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by…
- CVE-2019-193731 PoCAn issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to…
- CVE-2019-193741 PoCAn issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz…
- CVE-2019-193771 PoCIn the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a…
- CVE-2019-193781 PoCIn the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in…
- CVE-2019-193822 PoCsMax Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll…
- CVE-2019-193831 PoCfreeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).
- CVE-2019-193841 PoCA cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web…
- CVE-2019-193851 PoCA cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary…
- CVE-2019-193861 PoCA cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote…
- CVE-2019-193871 PoCA cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject…
- CVE-2019-193881 PoCA cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject…
- CVE-2019-193891 PoCJetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
- CVE-2019-193901 PoCThe Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters…
- CVE-2019-193931 PoCThe Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system…
- CVE-2019-194111 PoCUSG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200…
- CVE-2019-194472 PoCsIn the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a…
- CVE-2019-194481 PoCIn the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs…
- CVE-2019-194491 PoCIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in…
- CVE-2019-194521 PoCA buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low…
- CVE-2019-194571 PoCSALTO ProAccess SPACE 5.4.3.0 allows XSS.
- CVE-2019-194582 PoCsSALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
- CVE-2019-194591 PoCAn issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by…
- CVE-2019-194602 PoCsAn issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions…
- CVE-2019-194681 PoCFree Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers a malformed SEH,…
- CVE-2019-194702 PoCsUnsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local…
- CVE-2019-194891 PoCSMPlayer 19.5.0 has a buffer overflow via a long .m3u file.
- CVE-2019-194901 PoCLiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by…
- CVE-2019-194911 PoCTestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a…
- CVE-2019-194923 PoCsFreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
- CVE-2019-194932 PoCsKentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, leading to XSS.
- CVE-2019-194942 PoCsBroadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute…
- CVE-2019-194952 PoCsThe web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the…
- CVE-2019-194961 PoCAlfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
- CVE-2019-194971 PoCMDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
- CVE-2019-195002 PoCsMatrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment…
- CVE-2019-195051 PoCTenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the…
- CVE-2019-195061 PoCTenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By…
- CVE-2019-195071 PoCIn jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten…
- CVE-2019-195096 PoCsAn issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to…
- CVE-2019-195131 PoCThe BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may…
- CVE-2019-195163 PoCsIntelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a password.
- CVE-2019-195201 PoCxlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable,…
- CVE-2019-195221 PoCOpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by…
- CVE-2019-195401 PoCThe ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
- CVE-2019-195411 PoCThe ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.
- CVE-2019-195421 PoCThe ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
- CVE-2019-195471 PoCSymantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type…
- CVE-2019-195502 PoCsRemote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users…
- CVE-2019-195763 PoCsclass.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products,…
- CVE-2019-195851 PoCAn issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig…
- CVE-2019-195901 PoCIn radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c.…
- CVE-2019-195921 PoCJama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting
- CVE-2019-195941 PoCreset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers…
- CVE-2019-195951 PoCreset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows…
- CVE-2019-195971 PoCD-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters…
- CVE-2019-195981 PoCD-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header…
- CVE-2019-196011 PoCOpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf.
- CVE-2019-196051 PoCX-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code…
- CVE-2019-196061 PoCX-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak…
- CVE-2019-1960913 PoCsThe Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the…
- CVE-2019-196311 PoCAn issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through…
- CVE-2019-196321 PoCAn issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through…
- CVE-2019-196341 PoCclass.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other…
- CVE-2019-196421 PoCOn SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by…
- CVE-2019-196481 PoCIn the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially…
- CVE-2019-196972 PoCsAn arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an…
- CVE-2019-196992 PoCsThere is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration,…
- CVE-2019-197081 PoCThe VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key…
- CVE-2019-197191 PoCTableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
- CVE-2019-197266 PoCsOpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by…
- CVE-2019-197312 PoCsRoxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the…
- CVE-2019-197402 PoCsOcteth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
- CVE-2019-197422 PoCsOn D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
- CVE-2019-197432 PoCsOn D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
- CVE-2019-197461 PoCmake_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a…
- CVE-2019-197742 PoCsAn issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from…
- CVE-2019-197771 PoCstb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
- CVE-2019-197781 PoCAn issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
- CVE-2019-1978142 PoCsKEVAn issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory…
- CVE-2019-197822 PoCsThe FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
- CVE-2019-198131 PoCIn the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call…
- CVE-2019-198141 PoCIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access…
- CVE-2019-198151 PoCIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in…
- CVE-2019-198161 PoCIn the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write…
- CVE-2019-198201 PoCAn invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to…
- CVE-2019-198224 PoCsA certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the…
- CVE-2019-198233 PoCsA certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative…
- CVE-2019-198245 PoCsOn certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the…
- CVE-2019-198251 PoCOn certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the…
- CVE-2019-198291 PoCA cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability…
- CVE-2019-198321 PoCXerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The…
- CVE-2019-198333 PoCsIn Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be…
- CVE-2019-198421 PoCemfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the…
- CVE-2019-198445 PoCsDjango before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to…
- CVE-2019-198871 PoCbitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.
- CVE-2019-198881 PoCjfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.
- CVE-2019-198891 PoCAn issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the…
- CVE-2019-198901 PoCAn issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
- CVE-2019-199051 PoCNetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects…
- CVE-2019-199061 PoCcyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a…
- CVE-2019-199081 PoCphpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username…
- CVE-2019-199121 PoCIn Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows…
- CVE-2019-199131 PoCIn Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
- CVE-2019-199151 PoCThe "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify,…
- CVE-2019-199161 PoCIn Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent…
- CVE-2019-199191 PoCVersions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an…
- CVE-2019-199271 PoCIn the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and…
- CVE-2019-199301 PoCIn libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an…
- CVE-2019-199311 PoCIn libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.
- CVE-2019-199353 PoCsFroala Editor before 3.2.3 allows XSS.
- CVE-2019-199401 PoCIncorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote…
- CVE-2019-199411 PoCMissing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain…
- CVE-2019-199421 PoCMissing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro…
- CVE-2019-199431 PoCThe HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large…
- CVE-2019-199441 PoCIn libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.
- CVE-2019-199452 PoCsuhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a…
- CVE-2019-199461 PoCThe API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
- CVE-2019-199491 PoCIn ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to…
- CVE-2019-199501 PoCIn GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
- CVE-2019-199521 PoCIn ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
- CVE-2019-199541 PoCSignal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse…
- CVE-2019-199571 PoCIn libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to…
- CVE-2019-199581 PoCIn libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to…
- CVE-2019-199651 PoCIn the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of…
- CVE-2019-199661 PoCIn the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial…
- CVE-2019-199671 PoCThe Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password…
- CVE-2019-199792 PoCsA flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject…
- CVE-2019-199854 PoCsThe WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user…
- CVE-2019-199861 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication is able to execute…
- CVE-2019-199871 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any…
- CVE-2019-199881 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to create and…
- CVE-2019-199891 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are…
- CVE-2019-199901 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting (XSS)…
- CVE-2019-199911 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site scripting (XSS)…
- CVE-2019-199921 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to read XML…
- CVE-2019-199931 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnerability were…
- CVE-2019-199941 PoCAn issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without…