Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16130 1 Hgw168cc 1 Yii-cms 2019-09-09 4.3 MEDIUM 6.1 MEDIUM
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-9866 1 Gitlab 1 Gitlab 2019-09-09 4.0 MEDIUM 6.5 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.
CVE-2018-21013 1 Upperthemes 1 Swape 2019-09-09 7.5 HIGH 9.8 CRITICAL
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
CVE-2019-9245 1 Google 1 Android 2019-09-09 2.1 LOW 4.4 MEDIUM
In the Android kernel in the f2fs driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-9452 1 Google 1 Android 2019-09-09 2.1 LOW 4.4 MEDIUM
In the Android kernel in SEC_TS touch driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-9454 1 Google 1 Android 2019-09-09 4.6 MEDIUM 6.7 MEDIUM
In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-16123 1 Kartatopia 1 Piluscart 2019-09-09 5.0 MEDIUM 7.5 HIGH
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
CVE-2019-16141 1 Once Cell Project 1 Once Cell 2019-09-09 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
CVE-2019-9248 1 Google 1 Android 2019-09-09 4.6 MEDIUM 6.7 MEDIUM
In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-16142 1 Renderdocs-rs Project 1 Renderdocs-rs 2019-09-09 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.
CVE-2011-1572 1 Gitolite 1 Gitolite 2019-09-09 6.8 MEDIUM N/A
Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands.
CVE-2019-9271 1 Google 1 Android 2019-09-09 4.4 MEDIUM 6.4 MEDIUM
In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-after-free which could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2012-4506 2 Gitolite, Sitaram Chamarty 2 Gitolite, Gitolite 2019-09-09 4.6 MEDIUM N/A
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
CVE-2019-9426 1 Google 1 Android 2019-09-09 4.6 MEDIUM 6.7 MEDIUM
In the Android kernel in Bluetooth there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-16104 1 Silver-peak 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware 2019-09-09 4.3 MEDIUM 6.1 MEDIUM
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
CVE-2019-9270 1 Google 1 Android 2019-09-09 4.6 MEDIUM 7.8 HIGH
In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-9274 1 Google 1 Android 2019-09-09 4.6 MEDIUM 6.7 MEDIUM
In the Android kernel in the mnh driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-15944 1 Valvesoftware 1 Counter-strike\ 2019-09-09 5.0 MEDIUM 5.3 MEDIUM
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
CVE-2019-12588 1 Espressif 2 Arduino Esp8266, Esp8266 Nonos Sdk 2019-09-09 3.3 LOW 6.5 MEDIUM
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association responses, which allows attackers in radio range to cause a denial of service (crash) via a crafted message.
CVE-2019-16099 1 Silver-peak 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware 2019-09-09 6.8 MEDIUM 8.8 HIGH
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
CVE-2019-10677 1 Dasanzhone 2 Znid Gpon 2426a Eu, Znid Gpon 2426a Eu Firmware 2019-09-09 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).
CVE-2019-9444 1 Google 1 Android 2019-09-09 2.1 LOW 4.4 MEDIUM
In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-16105 1 Silver-peak 2 Unity Edgeconnect Sd-wan, Unity Edgeconnect Sd-wan Firmware 2019-09-09 4.0 MEDIUM 4.9 MEDIUM
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
CVE-2019-9448 1 Google 1 Android 2019-09-09 4.6 MEDIUM 6.7 MEDIUM
In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-9449 1 Google 1 Android 2019-09-09 2.1 LOW 4.4 MEDIUM
In the Android kernel in FingerTipS touchscreen driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
CVE-2015-9301 1 W3eden 1 Live Forms 2019-09-09 7.5 HIGH 9.8 CRITICAL
The liveforms plugin before 3.2.0 for WordPress has SQL injection.
CVE-2019-15128 1 If.svnadmin Project 1 If.svnadmin 2019-09-09 4.3 MEDIUM 6.5 MEDIUM
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
CVE-2019-16059 1 Sapplica 1 Sentrifugo 2019-09-09 6.8 MEDIUM 8.8 HIGH
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.
CVE-2017-18559 1 Cformsii Project 1 Cformsii 2019-09-08 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
CVE-2018-21007 1 Wisetr 1 User Email Verification For Woocommerce 2019-09-07 7.5 HIGH 9.8 CRITICAL
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
CVE-2017-18499 1 Simple-membership-plugin 1 Simple Membership 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The simple-membership plugin before 3.5.7 for WordPress has XSS.
CVE-2018-17583 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
CVE-2018-17584 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 6.8 MEDIUM 8.8 HIGH
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
CVE-2018-17585 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
CVE-2018-17586 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
CVE-2019-13917 2 Debian, Exim 2 Debian Linux, Exim 2019-09-07 10.0 HIGH 9.8 CRITICAL
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
CVE-2019-15952 1 Totaljs 1 Total.js Cms 2019-09-06 6.5 MEDIUM 8.8 HIGH
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.
CVE-2018-1000086 1 Npr 1 Pym.js 2019-09-06 6.8 MEDIUM 8.8 HIGH
NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.. This vulnerability appears to have been fixed in versions 1.3.2 and later.
CVE-2019-2103 1 Google 1 Android 2019-09-06 2.1 LOW 5.5 MEDIUM
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2018-11569 1 Eventum Project 1 Eventum 2019-09-06 7.5 HIGH 9.8 CRITICAL
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.
CVE-2019-13020 1 Trms 1 Tightrope Media Carousel 2019-09-06 6.4 MEDIUM 10.0 CRITICAL
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve malicious content from a third-party attacker-controlled system. Second, arguably more severe, is the potential for an attacker to circumvent firewall controls, by proxying traffic, unauthenticated, into the internal network from the internet.
CVE-2019-12223 1 Hanwha-security 6 Srn-1673s, Srn-1673s Firmware, Srn-472s and 3 more 2019-09-06 7.8 HIGH 7.5 HIGH
An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.
CVE-2019-10753 1 Diffplug 3 Eclipse-cdt, Eclipse-groovy, Eclipse-wtp 2019-09-06 4.3 MEDIUM 5.9 MEDIUM
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts that were produced. In case that any of these artifacts were compromised, any developers using these could be altered. **Note:** In order to validate that this artifact was not compromised, the maintainer would need to confirm that none of the artifacts published to the registry were not altered with. Until this happens, we can not guarantee that this artifact was not compromised even though the probability that this happened is low.
CVE-2019-15867 1 Omaksolutions 1 Slick-popup 2019-09-06 6.5 MEDIUM 8.8 HIGH
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
CVE-2019-2108 1 Google 1 Android 2019-09-06 9.3 HIGH 7.8 HIGH
In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2019-2176 1 Google 1 Android 2019-09-06 9.3 HIGH 7.8 HIGH
In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2019-2177 1 Google 1 Android 2019-09-06 6.8 MEDIUM 8.8 HIGH
In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2019-2178 1 Google 1 Android 2019-09-06 7.2 HIGH 7.8 HIGH
In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-13190 1 Eng 1 Knowage 2019-09-06 5.0 MEDIUM 5.3 MEDIUM
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
CVE-2016-10884 1 Simple-membership-plugin 1 Simple Membership 2019-09-06 6.8 MEDIUM 8.8 HIGH
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.