Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0868 1 Microsoft 2 Azure Devops Server, Team Foundation Server 2019-07-16 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0870, CVE-2019-0871.
CVE-2019-1071 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2019-07-16 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073.
CVE-2019-1073 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2019-07-16 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071.
CVE-2018-14833 1 Intuit 1 Lacerte 2019-07-16 4.3 MEDIUM 5.9 MEDIUM
Intuit Lacerte 2017 has Incorrect Access Control.
CVE-2019-12471 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2019-07-16 4.3 MEDIUM 6.1 MEDIUM
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
CVE-2018-19570 1 Gitlab 1 Gitlab 2019-07-16 3.5 LOW 5.4 MEDIUM
GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.
CVE-2018-19573 1 Gitlab 1 Gitlab 2019-07-16 3.5 LOW 5.4 MEDIUM
GitLab CE/EE, versions 10.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via Mermaid.
CVE-2018-19583 1 Gitlab 1 Gitlab 2019-07-16 4.0 MEDIUM 6.5 MEDIUM
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, permitting administrators with access to the logs to see another user's token.
CVE-2018-19574 1 Gitlab 1 Gitlab 2019-07-16 3.5 LOW 5.4 MEDIUM
GitLab CE/EE, versions 7.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in the OAuth authorization page.
CVE-2019-13505 1 Dwbooster 1 Appointment Hour Booking 2019-07-16 4.3 MEDIUM 6.1 MEDIUM
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
CVE-2019-12540 1 Zohocorp 1 Manageengine Servicedesk Plus 2019-07-15 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
CVE-2014-3798 1 Citrix 1 Xenserver 2019-07-15 6.1 MEDIUM 6.5 MEDIUM
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
CVE-2018-15738 1 Stopzilla 1 Antimalware 2019-07-15 2.1 LOW 5.5 MEDIUM
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000205F.
CVE-2019-5601 1 Freebsd 1 Freebsd 2019-07-15 4.0 MEDIUM 6.5 MEDIUM
In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.
CVE-2019-13114 1 Exiv2 1 Exiv2 2019-07-15 4.3 MEDIUM 6.5 MEDIUM
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
CVE-2018-19535 2 Debian, Exiv2 2 Debian Linux, Exiv2 2019-07-15 4.3 MEDIUM 6.5 MEDIUM
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
CVE-2019-13032 1 Flightcrew Project 1 Flightcrew 2019-07-15 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
CVE-2019-1010028 1 School College Portal With Erp Script Project 1 School College Portal With Erp Script 2019-07-15 4.3 MEDIUM 6.1 MEDIUM
phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.
CVE-2019-1010016 1 Dolibarr 1 Dolibarr 2019-07-15 4.3 MEDIUM 6.1 MEDIUM
Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.
CVE-2017-11580 1 Blipcare 2 Wi-fi Blood Pressure Monitor, Wi-fi Blood Pressure Monitor Firmware 2019-07-15 6.1 MEDIUM 6.5 MEDIUM
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely unresponsive. Presumably this happens as the memory footprint provided to this device is very small. According to the specs from Rezolt, the Wi-Fi module only has 256k of memory. As a result, an incorrect string copy operation using either memcpy, strcpy, or any of their other variants could result in filling up the memory space allocated to the function executing and this would result in memory corruption. To test the theory, one can modify the demo application provided by the Cypress WICED SDK and introduce an incorrect "memcpy" operation and use the compiled application on the evaluation board provided by Cypress semiconductors with exactly the same Wi-Fi SOC. The results were identical where the device would completely stop responding to any of the ping or web requests.
CVE-2017-11578 1 Blipcare 2 Wi-fi Blood Pressure Monitor, Wi-fi Blood Pressure Monitor Firmware 2019-07-15 4.3 MEDIUM 5.9 MEDIUM
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and have Internet access. This device acts as a Wireless Blood pressure monitor and is used to measure blood pressure levels of a person. This allows an attacker who is connected to the Blipcare's device wireless network to easily sniff these values using a MITM attack.
CVE-2019-0329 1 Sap 1 Information Steward 2019-07-14 4.3 MEDIUM 6.1 MEDIUM
SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2019-13488 1 Trape Project 1 Trape 2019-07-14 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter to the /register URI, because the jQuery prepend() method is used.
CVE-2017-2626 2 Freedesktop, Redhat 6 Libice, Enterprise Linux Desktop, Enterprise Linux Server and 3 more 2019-07-14 2.1 LOW 5.5 MEDIUM
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
CVE-2018-17152 1 Intersystems 1 Cache 2019-07-12 5.5 MEDIUM 6.4 MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XXE.
CVE-2018-17151 1 Intersystems 1 Cache 2019-07-12 5.5 MEDIUM 5.4 MEDIUM
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
CVE-2018-17150 1 Intersystems 1 Cache 2019-07-12 4.3 MEDIUM 6.1 MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XSS.
CVE-2019-1010003 1 Leanote 1 Leanote 2019-07-12 3.5 LOW 6.1 MEDIUM
Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
CVE-2019-1010314 1 Gitea 1 Gitea 2019-07-12 4.3 MEDIUM 6.1 MEDIUM
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.
CVE-2019-13562 1 Dlink 2 Dir-655, Dir-655 Firmware 2019-07-12 4.3 MEDIUM 6.1 MEDIUM
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.
CVE-2019-12748 1 Typo3 1 Typo3 2019-07-12 4.3 MEDIUM 6.1 MEDIUM
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
CVE-2019-13504 1 Exiv2 1 Exiv2 2019-07-12 4.3 MEDIUM 6.5 MEDIUM
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
CVE-2018-13809 1 Siemens 4 Cp 1604, Cp 1604 Firmware, Cp 1616 and 1 more 2019-07-11 4.3 MEDIUM 6.1 MEDIUM
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the affected CP devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into following a malicious link. User interaction is required for a successful exploitation. At the time of advisory publication no public exploitation of this vulnerability was known.
CVE-2018-13810 1 Siemens 4 Cp 1604, Cp 1604 Firmware, Cp 1616 and 1 more 2019-07-11 4.3 MEDIUM 6.5 MEDIUM
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. At the time of advisory publication no public exploitation of this vulnerability was known.
CVE-2018-19572 1 Gitlab 1 Gitlab 2019-07-11 4.3 MEDIUM 5.9 MEDIUM
GitLab CE 8.17 and later and EE 8.3 and later have a symlink time-of-check-to-time-of-use race condition that would allow unauthorized access to files in the GitLab Pages chroot environment. This is fixed in versions 11.5.1, 11.4.8, and 11.3.11.
CVE-2017-9327 1 Cloudera 1 Cloudera Manager 2019-07-11 4.0 MEDIUM 6.5 MEDIUM
Secret data of processes managed by CM is not secured by file permissions.
CVE-2018-19580 1 Gitlab 1 Gitlab 2019-07-11 5.0 MEDIUM 5.3 MEDIUM
All versions of GitLab prior to 11.5.1, 11.4.8, and 11.3.11 do not send an email to the old email address when an email address change is made.
CVE-2018-19579 1 Gitlab 1 Gitlab 2019-07-11 3.5 LOW 5.4 MEDIUM
GitLab EE version 11.5 is vulnerable to a persistent XSS vulnerability in the Operations page. This is fixed in 11.5.1.
CVE-2018-19578 1 Gitlab 1 Gitlab 2019-07-11 4.0 MEDIUM 6.5 MEDIUM
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
CVE-2018-19496 1 Gitlab 1 Gitlab 2019-07-11 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.
CVE-2018-19495 1 Gitlab 1 Gitlab 2019-07-11 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.
CVE-2018-19494 1 Gitlab 1 Gitlab 2019-07-11 4.0 MEDIUM 4.3 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.
CVE-2018-19493 1 Gitlab 1 Gitlab 2019-07-11 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.
CVE-2016-2460 1 Google 1 Android 2019-07-11 4.3 MEDIUM 5.5 MEDIUM
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBufferConsumer.cpp and IGraphicBufferProducer.cpp, aka internal bug 27555981.
CVE-2018-17147 1 Nagios 1 Nagios Xi 2019-07-11 3.5 LOW 4.8 MEDIUM
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVE-2019-8920 1 Apachefriends 1 Xampp 2019-07-11 4.3 MEDIUM 6.1 MEDIUM
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVE-2017-6217 1 Paypal 1 Adaptive Payments Sdk 2019-07-11 4.3 MEDIUM 6.1 MEDIUM
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
CVE-2017-18364 1 Frank-karau 1 Phpfk 2019-07-11 4.3 MEDIUM 6.1 MEDIUM
phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter.
CVE-2019-5967 1 Joruri 1 Joruri Cms 2017 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2019-13472 1 Phpwind 1 Phpwind 2019-07-10 4.3 MEDIUM 6.1 MEDIUM
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.