Search
Total
46623 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-20797 | 1 Podofo Project | 1 Podofo | 2019-02-27 | 4.3 MEDIUM | 6.5 MEDIUM |
| An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp. | |||||
| CVE-2018-9117 | 1 Wiremock | 1 Wiremock | 2019-02-27 | 5.0 MEDIUM | 5.3 MEDIUM |
| WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML request, aka Directory Traversal. | |||||
| CVE-2018-9842 | 1 Cyberark | 1 Password Vault | 2019-02-27 | 5.0 MEDIUM | 5.3 MEDIUM |
| CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. | |||||
| CVE-2018-8801 | 1 Gitlab | 1 Gitlab | 2019-02-27 | 4.0 MEDIUM | 6.5 MEDIUM |
| GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component. | |||||
| CVE-2018-11948 | 1 Qualcomm | 60 Msm8996au, Msm8996au Firmware, Qcs605 and 57 more | 2019-02-27 | 4.9 MEDIUM | 5.5 MEDIUM |
| Exceeding the limit of usage entries are not tracked and the information will be lost causing the content to lose continuity in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in versions MSM8996AU, QCS605, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130. | |||||
| CVE-2018-9244 | 1 Gitlab | 1 Gitlab | 2019-02-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7. | |||||
| CVE-2018-9243 | 1 Gitlab | 1 Gitlab | 2019-02-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7. | |||||
| CVE-2018-9304 | 1 Exiv2 | 1 Exiv2 | 2019-02-27 | 4.3 MEDIUM | 6.5 MEDIUM |
| In Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service. | |||||
| CVE-2018-9163 | 1 Zohocorp | 1 Manageengine Recovery Manager Plus | 2019-02-27 | 3.5 LOW | 5.4 MEDIUM |
| A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do. | |||||
| CVE-2019-8410 | 1 Maccms | 1 Maccms | 2019-02-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key). | |||||
| CVE-2019-7156 | 1 Libdoc Project | 1 Libdoc | 2019-02-27 | 4.3 MEDIUM | 6.5 MEDIUM |
| In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero. | |||||
| CVE-2019-8939 | 1 Tautulli | 1 Tautulli | 2019-02-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page. | |||||
| CVE-2019-6595 | 1 F5 | 1 Big-ip Access Policy Manager | 2019-02-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI. | |||||
| CVE-2018-20232 | 1 Atlassian | 1 Jira | 2019-02-27 | 3.5 LOW | 5.4 MEDIUM |
| The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting. | |||||
| CVE-2018-13912 | 1 Qualcomm | 72 Mdm9150, Mdm9150 Firmware, Mdm9206 and 69 more | 2019-02-26 | 2.1 LOW | 5.5 MEDIUM |
| Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24. | |||||
| CVE-2019-0647 | 1 Microsoft | 1 Team Foundation Server | 2019-02-26 | 4.0 MEDIUM | 6.5 MEDIUM |
| An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team Foundation Server Information Disclosure Vulnerability." This affects Team. | |||||
| CVE-2018-11935 | 1 Qualcomm | 56 Mdm9607, Mdm9607 Firmware, Mdm9650 and 53 more | 2019-02-26 | 5.0 MEDIUM | 5.3 MEDIUM |
| Improper input validation might result in incorrect app id returned to the caller Instead of returning failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130. | |||||
| CVE-2018-20010 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. | |||||
| CVE-2019-6263 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | |||||
| CVE-2019-6261 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability. | |||||
| CVE-2019-6262 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS. | |||||
| CVE-2016-5016 | 1 Pivotal Software | 4 Cloud Foundry, Cloud Foundry Elastic Runtime, Cloud Foundry Uaa and 1 more | 2019-02-26 | 4.3 MEDIUM | 5.9 MEDIUM |
| Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired. | |||||
| CVE-2018-20240 | 1 Atlassian | 2 Crucible, Fisheye | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. | |||||
| CVE-2018-20241 | 1 Atlassian | 2 Crucible, Fisheye | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter. | |||||
| CVE-2019-6264 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability. | |||||
| CVE-2018-20787 | 1 Micode | 1 Xiaomi Perseus-p-oss | 2019-02-26 | 7.1 HIGH | 5.5 MEDIUM |
| The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the size argument in tpdbg_write in drivers/input/touchscreen/ft5x46/ft5x46_ts.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device. | |||||
| CVE-2018-20788 | 1 Micode | 1 Xiaomi Perseus-p-oss | 2019-02-26 | 4.3 MEDIUM | 5.5 MEDIUM |
| drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand operand can be equal to or greater than the integer length. This can be exploited by a crafted application for denial of service. | |||||
| CVE-2019-9168 | 1 Woocommerce | 1 Woocommerce | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. | |||||
| CVE-2019-9111 | 1 Micode | 1 Xiaomi Perseus-p-oss | 2019-02-26 | 7.1 HIGH | 5.5 MEDIUM |
| The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in sde_evtlog_filter_write in drivers/gpu/drm/msm/sde_dbg.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device. | |||||
| CVE-2018-19914 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | |||||
| CVE-2016-4995 | 1 Theforeman | 1 Foreman | 2019-02-26 | 3.5 LOW | 5.3 MEDIUM |
| Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname. | |||||
| CVE-2019-9112 | 1 Micode | 1 Xiaomi Perseus-p-oss | 2019-02-26 | 7.1 HIGH | 5.5 MEDIUM |
| The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in _sde_debugfs_conn_cmd_tx_write in drivers/gpu/drm/msm/sde/sde_connector.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device. | |||||
| CVE-2018-20011 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. | |||||
| CVE-2019-7312 | 1 Primx | 3 Zed, Zedmail, Zonecentral | 2019-02-26 | 5.0 MEDIUM | 5.3 MEDIUM |
| Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) before 6.1.2150, Zed Entreprise for Mac before 2.0.199, Zed Entreprise for Linux before 2.0.199, Zed Pro for Windows before 1.0.195, Zed Pro for Mac before 1.0.199, Zed Pro for Linux before 1.0.199, Zed Free for Windows before 1.0.195, Zed Free for Mac before 1.0.199, and Zed Free for Linux before 1.0.199. Analyzing a Zed container can lead to the disclosure of plaintext content of very small files (a few bytes) stored into it. | |||||
| CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |||||
| CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |||||
| CVE-2018-20009 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. | |||||
| CVE-2018-16632 | 1 Jupo | 1 Mezzanine | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | |||||
| CVE-2018-19598 | 1 Statamic | 1 Statamic | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request. | |||||
| CVE-2018-19915 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | |||||
| CVE-2019-8394 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2019-02-26 | 4.0 MEDIUM | 6.5 MEDIUM |
| Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | |||||
| CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | |||||
| CVE-2019-9145 | 1 Hsycms | 1 Hsycms | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page. | |||||
| CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | |||||
| CVE-2018-16631 | 1 Intelliants | 1 Subrion Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. | |||||
| CVE-2018-16629 | 1 Intelliants | 1 Subrion Cms | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | |||||
| CVE-2018-16630 | 1 Getkirby | 1 Kirby | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
| Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file. | |||||
| CVE-2018-16627 | 1 Getkirby | 1 Kirby | 2019-02-26 | 5.8 MEDIUM | 6.1 MEDIUM |
| panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. | |||||
| CVE-2018-16628 | 1 Getkirby | 1 Kirby | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
| panel/login in Kirby v2.5.12 allows XSS via a blog name. | |||||
| CVE-2018-11627 | 2 Redhat, Sinatrarb | 2 Cloudforms, Sinatra | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. | |||||
