Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9478 1 No-margin-for-error 1 Prettyphoto 2019-10-15 4.3 MEDIUM 6.1 MEDIUM
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
CVE-2019-0381 1 Sap 3 Dynamic Tier, Sap Iq, Sql Anywhere 2019-10-15 2.1 LOW 5.5 MEDIUM
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.
CVE-2019-17108 1 Centreon 1 Centreon Web 2019-10-15 4.3 MEDIUM 6.1 MEDIUM
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
CVE-2019-17105 1 Centreon 1 Centreon Web 2019-10-15 5.0 MEDIUM 5.3 MEDIUM
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
CVE-2018-21023 1 Centreon 1 Centreon Web 2019-10-15 6.5 MEDIUM 8.8 HIGH
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
CVE-2015-9460 1 Pinpoint 1 Pinpoint Booking System 2019-10-15 6.5 MEDIUM 8.8 HIGH
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
CVE-2018-21024 1 Centreon 1 Centreon 2019-10-15 7.5 HIGH 9.8 CRITICAL
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
CVE-2019-10757 1 Knexjs 1 Knex 2019-10-15 7.5 HIGH 9.8 CRITICAL
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
CVE-2019-17386 1 Eleopard 1 Animate It\! 2019-10-15 6.8 MEDIUM 8.8 HIGH
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
CVE-2019-17488 1 B3log 1 Symphony 2019-10-15 4.3 MEDIUM 6.1 MEDIUM
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
CVE-2015-9462 1 Awesome Filterable Portfolio Project 1 Awesome Filterable Portfolio 2019-10-15 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.
CVE-2019-1375 1 Microsoft 1 Dynamics 365 2019-10-15 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
CVE-2018-16551 1 Lavalite 1 Lavalite 2019-10-15 3.5 LOW 5.4 MEDIUM
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
CVE-2016-10894 2 Debian, Xtrlock Project 2 Debian Linux, Xtrlock 2019-10-15 2.1 LOW 4.6 MEDIUM
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad once and then clicking with a different finger).
CVE-2019-17092 1 Openproject 1 Openproject 2019-10-14 4.3 MEDIUM 6.1 MEDIUM
An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.
CVE-2019-17263 1 Libfwsi Project 1 Libfwsi 2019-10-14 2.1 LOW 3.3 LOW
** DISPUTED ** In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap-based buffer over-read because rejection of an unsupported size only considers values less than 6, even though values of 6 and 7 are also unsupported. NOTE: the vendor has disputed this as described in the GitHub issue.
CVE-2016-10873 1 Wpseeds 1 Wp Database Backup 2019-10-12 4.3 MEDIUM 6.1 MEDIUM
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
CVE-2016-10874 1 Wpseeds 1 Wp Database Backup 2019-10-12 6.8 MEDIUM 8.8 HIGH
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
CVE-2018-7866 2 Debian, Libming 2 Debian Linux, Libming 2019-10-12 4.3 MEDIUM 6.5 MEDIUM
A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVE-2018-7876 2 Debian, Libming 2 Debian Linux, Libming 2019-10-12 4.3 MEDIUM 6.5 MEDIUM
In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.
CVE-2018-9009 2 Debian, Libming 2 Debian Linux, Libming 2019-10-12 6.8 MEDIUM 8.8 HIGH
In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.
CVE-2018-9132 2 Debian, Libming 2 Debian Linux, Libming 2019-10-12 4.3 MEDIUM 6.5 MEDIUM
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.
CVE-2018-10103 1 Tcpdump 1 Tcpdump 2019-10-11 7.5 HIGH 9.8 CRITICAL
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).
CVE-2018-10105 1 Tcpdump 1 Tcpdump 2019-10-11 7.5 HIGH 9.8 CRITICAL
tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).
CVE-2018-16300 1 Tcpdump 1 Tcpdump 2019-10-11 5.0 MEDIUM 7.5 HIGH
The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.
CVE-2018-16452 1 Tcpdump 1 Tcpdump 2019-10-11 5.0 MEDIUM 7.5 HIGH
The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.
CVE-2019-17429 1 Adhouma Cms Project 1 Adhouma Cms 2019-10-11 7.5 HIGH 9.8 CRITICAL
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-1070 1 Microsoft 1 Sharepoint Enterprise Server 2019-10-11 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
CVE-2019-1357 1 Microsoft 9 Edge, Internet Explorer, Windows 10 and 6 more 2019-10-11 4.3 MEDIUM 4.3 MEDIUM
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
CVE-2019-1060 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2019-10-11 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
CVE-2019-17431 1 Fastadmin 1 Fastadmin 2019-10-11 6.8 MEDIUM 8.8 HIGH
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
CVE-2019-17128 1 Netreo 1 Omnicenter 2019-10-11 5.0 MEDIUM 7.5 HIGH
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows an attacker to read sensitive information from the database used by the application.
CVE-2019-12707 1 Cisco 3 Unified Communications Manager, Unified Communications Manager Im And Presence Service, Unity Connection 2019-10-11 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
CVE-2019-17452 1 Axiosys 1 Bento4 2019-10-11 4.3 MEDIUM 6.5 MEDIUM
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.
CVE-2019-17417 1 Pbootcms 1 Pbootcms 2019-10-11 3.5 LOW 4.8 MEDIUM
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-17187 1 Fiberhome 2 Hg2201t, Hg2201t Firmware 2019-10-11 5.0 MEDIUM 7.5 HIGH
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
CVE-2019-17131 1 Vbulletin 1 Vbulletin 2019-10-11 4.3 MEDIUM 4.3 MEDIUM
vBulletin before 5.5.4 allows clickjacking.
CVE-2019-3745 1 Dell 2 Encryption, Endpoint Security Suite Enterprise 2019-10-11 6.9 MEDIUM 7.3 HIGH
The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.
CVE-2019-1363 1 Microsoft 2 Windows 7, Windows Server 2008 2019-10-11 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
CVE-2019-1328 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Foundation 2019-10-11 3.5 LOW 5.4 MEDIUM
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
CVE-2019-1329 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Foundation 2019-10-11 3.5 LOW 5.4 MEDIUM
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1330.
CVE-2019-17454 1 Axiosys 1 Bento4 2019-10-11 4.3 MEDIUM 6.5 MEDIUM
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.
CVE-2019-17453 1 Axiosys 1 Bento4 2019-10-11 4.3 MEDIUM 6.5 MEDIUM
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.
CVE-2018-21025 1 Centreon 1 Centreon Vm 2019-10-11 10.0 HIGH 9.8 CRITICAL
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.
CVE-2019-17104 1 Centreon 1 Centreon Vm 2019-10-11 5.0 MEDIUM 7.5 HIGH
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
CVE-2018-21020 1 Centreon 1 Centreon Web 2019-10-11 5.0 MEDIUM 7.5 HIGH
In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authentication mechanisms in place.
CVE-2019-13051 1 Pi-hole 1 Pi-hole 2019-10-11 6.8 MEDIUM 8.8 HIGH
Pi-Hole 4.3 allows Command Injection.
CVE-2015-9467 1 K-78 1 Broken Link Manager 2019-10-11 7.5 HIGH 9.8 CRITICAL
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
CVE-2015-9461 1 Brinidesigner 1 Awesome Filterable Portfolio 2019-10-11 6.5 MEDIUM 7.2 HIGH
The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.
CVE-2019-17401 1 Liblnk Project 1 Liblnk 2019-10-11 2.1 LOW 3.3 LOW
** DISPUTED ** libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue than CVE-2019-17264. NOTE: the vendor has disputed this as described in the GitHub issue.