Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-4397 1 Ibm 2 Cloud Orchestrator, Cloud Orchestrator Enterprise 2019-10-30 4.0 MEDIUM 6.5 MEDIUM
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 162239
CVE-2019-4409 1 Hcltech 1 Traveler 2019-10-30 3.5 LOW 5.4 MEDIUM
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.
CVE-2019-18212 3 Eclipse, Theia Xml Extension Project, Xml Language Server Project 3 Wild Web Developer, Theia Xml Extension, Xml Server Project 2019-10-30 4.0 MEDIUM 6.5 MEDIUM
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.
CVE-2018-12153 1 Intel 1 Graphics Driver 2019-10-30 4.9 MEDIUM 6.5 MEDIUM
Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user from a virtual machine guest to potentially crash the host system via local access.
CVE-2018-12154 1 Intel 1 Graphics Driver 2019-10-30 2.1 LOW 5.5 MEDIUM
Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user to potentially create an infinite loop and crash an application via local access.
CVE-2017-7152 1 Apple 1 Iphone Os 2019-10-30 4.3 MEDIUM 4.3 MEDIUM
An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail Message Framework" component. It allows remote attackers to spoof the address bar via a crafted web site.
CVE-2010-4240 1 Tiki 1 Tikiwiki Cms\/groupware 2019-10-29 4.3 MEDIUM 6.1 MEDIUM
Tiki Wiki CMS Groupware 5.2 has XSS
CVE-2018-0504 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2019-10-29 4.0 MEDIUM 6.5 MEDIUM
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
CVE-2019-9763 1 Openfind 1 Mail2000 2019-10-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
CVE-2019-4330 1 Ibm 1 Security Guardium Big Data Intelligence 2019-10-29 4.3 MEDIUM 4.3 MEDIUM
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.
CVE-2019-4306 1 Ibm 1 Security Guardium Big Data Intelligence 2019-10-29 6.4 MEDIUM 6.5 MEDIUM
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.
CVE-2019-4309 1 Ibm 1 Security Guardium Big Data Intelligence 2019-10-29 2.1 LOW 5.5 MEDIUM
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.
CVE-2017-1321 1 Ibm 2 Infosphere Information Server, Infosphere Information Server On Cloud 2019-10-29 4.3 MEDIUM 6.1 MEDIUM
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125916.
CVE-2019-18221 1 Corehr 1 Core Portal 2019-10-29 4.3 MEDIUM 6.1 MEDIUM
CoreHR Core Portal before 27.0.7 allows stored XSS.
CVE-2013-4856 1 D-link 2 Dir-865l, Dir-865l Firmware 2019-10-29 2.9 LOW 6.5 MEDIUM
D-Link DIR-865L has Information Disclosure.
CVE-2019-18350 1 Ant.design 1 Ant Design Pro 2019-10-29 4.3 MEDIUM 6.1 MEDIUM
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
CVE-2019-4459 1 Ibm 1 Cloud Orchestrator 2019-10-28 3.5 LOW 5.4 MEDIUM
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163656.
CVE-2019-3982 1 Tenable 1 Nessus 2019-10-28 4.0 MEDIUM 6.5 MEDIUM
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types. An authenticated, remote attacker could potentially exploit this vulnerability to cause a Nessus scanner to become temporarily unresponsive.
CVE-2019-4486 1 Ibm 9 Maximo Asset Management, Maximo For Aviation, Maximo For Life Sciences and 6 more 2019-10-28 3.5 LOW 5.4 MEDIUM
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.
CVE-2019-17143 1 Foxitsoftware 1 Phantompdf 2019-10-28 4.3 MEDIUM 4.3 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-9273.
CVE-2016-3101 1 Jenkins 1 Extra Columns 2019-10-28 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
CVE-2016-4988 1 Jenkins 1 Build Failure Analyzer 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
CVE-2016-4987 1 Jenkins 1 Image Gallery 2019-10-28 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
CVE-2019-17581 1 Dormsystem Project 1 Dormsystem 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
tonyy dormsystem through 1.3 allows DOM XSS.
CVE-2019-18415 1 Restaurant Management System Project 1 Restaurant Management System 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
CVE-2019-18416 1 Restaurant Management System Project 1 Restaurant Management System 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
CVE-2019-17606 1 Hexo-admin Project 1 Hexo-admin 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
CVE-2017-16355 2 Debian, Phusion 2 Debian Linux, Passenger 2019-10-28 1.2 LOW 4.7 MEDIUM
In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.
CVE-2019-9597 1 Darktrace 1 Enterprise Immune System 2019-10-28 4.3 MEDIUM 6.5 MEDIUM
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
CVE-2019-9596 1 Darktrace 1 Enterprise Immune System 2019-10-28 4.3 MEDIUM 6.5 MEDIUM
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
CVE-2019-18357 1 Thycotic 1 Secret Server 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
CVE-2019-18356 1 Thycotic 1 Secret Server 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
CVE-2019-17138 1 Foxitsoftware 1 Foxit Studio Photo 2019-10-28 4.3 MEDIUM 4.3 MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion from JPEG to EPS. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8809.
CVE-2019-4400 1 Ibm 1 Cloud Orchestrator 2019-10-28 4.0 MEDIUM 4.3 MEDIUM
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162261.
CVE-2019-16976 1 Fusionpbx 1 Fusionpbx 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
CVE-2019-16977 1 Fusionpbx 1 Fusionpbx 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-8080 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Successful exploitation could lead to privilege escalation.
CVE-2019-8085 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2019-8078 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2019-8079 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2019-8234 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.5 MEDIUM
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2015-9504 1 Weeklynews Theme Project 1 Weeklynews Theme 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
CVE-2019-8084 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2019-8083 1 Adobe 1 Experience Manager 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2015-9503 1 Webmandesign 1 Modern Theme 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9502 1 Webmandesign 1 Auberge Theme 2019-10-28 4.3 MEDIUM 6.1 MEDIUM
The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2019-15164 1 Tcpdump 1 Libpcap 2019-10-27 5.0 MEDIUM 5.3 MEDIUM
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
CVE-2019-15162 2 Opengroup, Tcpdump 2 Unix, Libpcap 2019-10-27 5.0 MEDIUM 5.3 MEDIUM
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
CVE-2019-17350 1 Xen 1 Xen 2019-10-26 4.9 MEDIUM 5.5 MEDIUM
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.
CVE-2019-17349 1 Xen 1 Xen 2019-10-26 4.9 MEDIUM 5.5 MEDIUM
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.