Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-3151 1 Canonical 1 Selinux 2019-10-09 5.8 MEDIUM 5.9 MEDIUM
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem.
CVE-2011-4190 1 Suse 2 Suse Linux Enterprise Desktop, Suse Linux Enterprise Server 2019-10-09 3.5 LOW 5.3 MEDIUM
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).
CVE-2009-0783 1 Apache 1 Tomcat 2019-10-09 4.6 MEDIUM 4.2 MEDIUM
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.
CVE-2019-17384 1 Eleopard 1 Animate It\! 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
The animate-it plugin before 2.3.4 for WordPress has XSS.
CVE-2019-17385 1 Eleopard 1 Animate It\! 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
The animate-it plugin before 2.3.5 for WordPress has XSS.
CVE-2019-4512 1 Ibm 10 Control Desk, Maximo Asset Management, Maximo For Aviation and 7 more 2019-10-09 4.0 MEDIUM 4.3 MEDIUM
IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164554.
CVE-2019-17271 1 Vbulletin 1 Vbulletin 2019-10-09 4.0 MEDIUM 4.9 MEDIUM
vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
CVE-2019-17378 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
CVE-2019-17377 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
CVE-2019-17379 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
CVE-2019-17376 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
CVE-2019-16416 1 Hrworks 1 Hrworks 2019-10-09 3.5 LOW 5.4 MEDIUM
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-16417 1 Hrworks 1 Hrworks 2019-10-09 3.5 LOW 5.4 MEDIUM
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-6648 2 F5, Redhat 2 Container Ingress Service, Openshift 2019-10-09 1.9 LOW 4.4 MEDIUM
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration.
CVE-2019-6653 1 F5 1 Big-iq Centralized Management 2019-10-09 3.5 LOW 5.4 MEDIUM
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.
CVE-2019-6651 1 F5 16 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 13 more 2019-10-09 5.0 MEDIUM 5.3 MEDIUM
In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.
CVE-2019-17368 1 S-cms 1 S-cms 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
CVE-2019-17380 1 Cpanel 1 Cpanel 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVE-2019-16931 1 Themeisle 1 Visualizer 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via the admin dashboard. This occurs because classes/Visualizer/Gutenberg/Block.php registers wp-json/visualizer/v1/update-chart with no access control, and classes/Visualizer/Render/Page/Data.php lacks output sanitization.
CVE-2019-16198 1 Kslabs 1 Ksweb 2019-10-09 4.0 MEDIUM 6.5 MEDIUM
KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
CVE-2019-15499 2 Apple, Hackmd 2 Safari, Codimd 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
CVE-2019-4342 1 Ibm 1 Cognos Analytics 2019-10-09 3.5 LOW 5.4 MEDIUM
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421.
CVE-2019-15750 1 Sitos 1 Sitos Six 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2019-15749 1 Sitos 1 Sitos Six 2019-10-09 4.3 MEDIUM 6.5 MEDIUM
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.
CVE-2016-1144 1 Websquare 1 Job-cube 2019-10-08 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2019-15041 1 Jetbrains 1 Youtrack 2019-10-08 5.8 MEDIUM 6.1 MEDIUM
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
CVE-2019-11656 1 Hp 1 Arcsight Logger 2019-10-08 3.5 LOW 5.4 MEDIUM
Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. This vulnerability could allow Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
CVE-2019-14957 1 Jetbrains 1 Vim 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.
CVE-2019-12737 1 Jetbrains 1 Ktor 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
CVE-2019-17213 1 Webarxsecurity 1 Webarx 2019-10-08 4.3 MEDIUM 6.1 MEDIUM
The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
CVE-2019-17121 1 Vanderbilt 1 Redcap 2019-10-08 3.5 LOW 5.4 MEDIUM
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
CVE-2019-17225 1 Intelliants 1 Subrion 2019-10-08 3.5 LOW 5.4 MEDIUM
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
CVE-2019-17226 1 Cmsmadesimple 1 Cms Made Simple 2019-10-08 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
CVE-2019-16332 1 Api Bearer Auth Project 1 Api Bearer Auth 2019-10-08 4.3 MEDIUM 6.1 MEDIUM
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
CVE-2019-14955 1 Jetbrains 1 Hub 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.
CVE-2017-18102 1 Atlassian 1 Jira 2019-10-08 3.5 LOW 5.4 MEDIUM
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup.
CVE-2019-17203 1 Teampass 1 Teampass 2019-10-08 3.5 LOW 5.4 MEDIUM
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
CVE-2019-17204 1 Teampass 1 Teampass 2019-10-08 3.5 LOW 5.4 MEDIUM
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
CVE-2019-17205 1 Teampass 1 Teampass 2019-10-08 4.3 MEDIUM 6.1 MEDIUM
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
CVE-2018-1000547 1 Corebos 1 Corebos 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no permissions to. .
CVE-2018-7274 1 Quarx Cms Project 1 Quarx Cms 2019-10-07 4.3 MEDIUM 6.1 MEDIUM
Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name).
CVE-2019-17074 1 Xunruicms 1 Xunruicms 2019-10-07 3.5 LOW 5.4 MEDIUM
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
CVE-2019-9312 1 Google 1 Android 2019-10-07 2.1 LOW 5.5 MEDIUM
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78288018
CVE-2019-9356 1 Google 1 Android 2019-10-07 1.9 LOW 5.0 MEDIUM
In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111699773
CVE-2019-9246 1 Google 1 Android 2019-10-07 1.9 LOW 5.0 MEDIUM
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637
CVE-2018-19975 1 Virustotal 1 Yara 2019-10-06 7.1 HIGH 5.5 MEDIUM
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD.
CVE-2018-19976 1 Virustotal 1 Yara 2019-10-06 4.3 MEDIUM 5.5 MEDIUM
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine.
CVE-2019-11747 1 Mozilla 2 Firefox, Firefox Esr 2019-10-05 4.3 MEDIUM 6.5 MEDIUM
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-load list also have their HSTS setting removed. On the next visit to that site if the user specifies an http: URL rather than secure https: they will not be protected by the pre-loaded HSTS setting. After that visit the site's HSTS setting will be restored. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
CVE-2019-8290 1 Online Store System Project 1 Online Store System 2019-10-04 4.3 MEDIUM 6.1 MEDIUM
Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected.
CVE-2019-11744 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2019-10-04 4.3 MEDIUM 6.1 MEDIUM
Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for other elements. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.