Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-17579 1 Sonarsource 1 Sonarqube 2019-10-17 4.3 MEDIUM 6.1 MEDIUM
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
CVE-2017-14955 1 Tribe29 1 Checkmk 2019-10-17 4.3 MEDIUM 5.9 MEDIUM
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
CVE-2019-16344 1 Scadabr 1 Scadabr 2019-10-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password parameter.
CVE-2015-1828 1 Http.rb Project 1 Http.rb 2019-10-17 4.3 MEDIUM 5.9 MEDIUM
The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.
CVE-2019-14226 1 Open-xchange 1 Open-xchange Appsuite 2019-10-17 5.5 MEDIUM 8.1 HIGH
OX App Suite through 7.10.2 has Insecure Permissions.
CVE-2017-14683 1 Geminabox Project 1 Geminabox 2019-10-17 6.8 MEDIUM 8.8 HIGH
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
CVE-2017-14506 1 Geminabox Project 1 Geminabox 2019-10-17 3.5 LOW 5.4 MEDIUM
geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.
CVE-2019-15902 4 Debian, Linux, Netapp and 1 more 7 Debian Linux, Linux Kernel, Active Iq Performance Analytics Services and 4 more 2019-10-17 4.7 MEDIUM 5.6 MEDIUM
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre vulnerability that it aimed to eliminate. This occurred because the backport process depends on cherry picking specific commits, and because two (correctly ordered) code lines were swapped.
CVE-2018-20582 1 Gree 1 Gree\+ 2019-10-17 6.8 MEDIUM 8.8 HIGH
The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
CVE-2018-21027 1 Boa 1 Boa 2019-10-17 7.5 HIGH 9.8 CRITICAL
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
CVE-2019-17537 1 Jnoj 1 Jiangnan Online Judge 2019-10-17 6.4 MEDIUM 7.5 HIGH
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
CVE-2019-17538 1 Jnoj 1 Jiangnan Online Judge 2019-10-17 5.0 MEDIUM 7.5 HIGH
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
CVE-2018-11790 2 Apache, Canonical 2 Open Office, Ubuntu Linux 2019-10-17 4.6 MEDIUM 7.8 HIGH
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
CVE-2018-15909 5 Artifex, Canonical, Debian and 2 more 11 Ghostscript, Gpl Ghostscript, Ubuntu Linux and 8 more 2019-10-16 6.8 MEDIUM 7.8 HIGH
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
CVE-2019-17625 1 Rambox 1 Rambox 2019-10-16 8.5 HIGH 9.0 CRITICAL
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
CVE-2015-9469 1 Cybercraftit 1 Content-grabber 2019-10-16 3.5 LOW 4.8 MEDIUM
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
CVE-2016-6800 1 Apache 1 Ofbiz 2019-10-16 4.3 MEDIUM 6.1 MEDIUM
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01.
CVE-2019-16282 1 Nchsoftware 1 Express Invoice 2019-10-16 3.5 LOW 5.4 MEDIUM
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.
CVE-2019-17552 1 Idreamsoft 1 Icms 2019-10-16 7.5 HIGH 9.8 CRITICAL
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
CVE-2005-0758 2 Canonical, Gnu 2 Ubuntu Linux, Gzip 2019-10-16 4.6 MEDIUM N/A
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
CVE-2019-4572 1 Ibm 1 Filenet Content Manager 2019-10-16 2.1 LOW 4.4 MEDIUM
IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into a log file that could be accessed by an administrator on the local machine. IBM X-Force ID: 166798.
CVE-2019-17593 1 Jizhicms 1 Jizhicms 2019-10-16 6.8 MEDIUM 8.8 HIGH
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
CVE-2019-17580 1 Dormsystem Project 1 Dormsystem 2019-10-16 7.5 HIGH 9.8 CRITICAL
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2017-1002151 1 Redhat 1 Pagure 2019-10-16 5.0 MEDIUM 7.5 HIGH
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
CVE-2019-17490 1 Jnoj 1 Jiangnan Online Judge 2019-10-16 6.5 MEDIUM 8.8 HIGH
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content type) to the web/polygon/problem/tests URI.
CVE-2015-4075 1 Helpdeskpro 1 Helpdesk Pro 2019-10-16 6.8 MEDIUM 8.1 HIGH
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
CVE-2018-1002204 1 Adm-zip Project 1 Adm-zip 2019-10-16 4.3 MEDIUM 5.5 MEDIUM
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVE-2015-9457 1 Caseproof 1 Pretty Link 2019-10-16 6.5 MEDIUM 7.2 HIGH
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
CVE-2018-21028 1 Boa 1 Boa 2019-10-16 5.0 MEDIUM 7.5 HIGH
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
CVE-2015-9470 1 Ionadas 1 History Collection 2019-10-16 5.0 MEDIUM 7.5 HIGH
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
CVE-2019-17629 1 Cmsmadesimple 1 Cms Made Simple 2019-10-16 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
CVE-2019-17630 1 Cmsmadesimple 1 Cms Made Simple 2019-10-16 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
CVE-2019-17176 1 Genesys 1 Eservices Chat 2019-10-16 4.3 MEDIUM 6.1 MEDIUM
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).
CVE-2010-5335 1 Icewarp 1 Webclient 2019-10-16 7.8 HIGH 7.5 HIGH
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.
CVE-2018-18065 5 Canonical, Debian, Net-snmp and 2 more 10 Ubuntu Linux, Debian Linux, Net-snmp and 7 more 2019-10-16 4.0 MEDIUM 6.5 MEDIUM
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVE-2018-18066 2 Net-snmp, Netapp 7 Net-snmp, Cloud Backup, Data Ontap and 4 more 2019-10-16 5.0 MEDIUM 7.5 HIGH
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVE-2019-17497 1 Tracker-software 1 Pdf-xchange Editor 2019-10-16 4.3 MEDIUM 6.5 MEDIUM
Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.
CVE-2019-9534 1 Cobham 2 Explorer 710, Explorer 710 Firmware 2019-10-16 7.2 HIGH 7.8 HIGH
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify traffic, spoof or intercept GPS traffic, exfiltrate private data, hide a backdoor, or cause a denial-of-service.
CVE-2019-2183 1 Google 1 Android 2019-10-16 2.1 LOW 5.5 MEDIUM
In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching optimization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-136261465
CVE-2019-2184 1 Google 1 Android 2019-10-16 9.3 HIGH 8.8 HIGH
In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-134578122
CVE-2019-2173 1 Google 1 Android 2019-10-16 4.6 MEDIUM 7.8 HIGH
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-123013720
CVE-2019-2185 1 Google 1 Android 2019-10-16 9.3 HIGH 8.8 HIGH
In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-136173699
CVE-2019-2186 1 Google 1 Android 2019-10-16 9.3 HIGH 8.8 HIGH
In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-136175447
CVE-2019-14225 1 Open-xchange 1 Open-xchange Appsuite 2019-10-16 5.5 MEDIUM 5.4 MEDIUM
OX App Suite 7.10.1 and 7.10.2 allows SSRF.
CVE-2019-14227 1 Open-xchange 1 Open-xchange Appsuite 2019-10-16 4.3 MEDIUM 6.1 MEDIUM
OX App Suite 7.10.1 and 7.10.2 allows XSS.
CVE-2019-17535 1 Gilacms 1 Gila Cms 2019-10-16 4.3 MEDIUM 6.1 MEDIUM
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
CVE-2015-9492 1 Smartit Premium Responsive Project 1 Smartit Premium Responsive 2019-10-16 5.0 MEDIUM 7.5 HIGH
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
CVE-2019-17369 1 Otcms 1 Otcms 2019-10-16 4.3 MEDIUM 6.5 MEDIUM
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
CVE-2015-9474 1 Simpolio Project 1 Simpolio 2019-10-16 6.5 MEDIUM 8.8 HIGH
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
CVE-2015-9475 1 Pont Project 1 Pont 2019-10-16 6.5 MEDIUM 8.8 HIGH
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.