Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-7882 1 Magento 1 Magento 2019-08-07 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting vulnerability exists in the WYSIWYG editor of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the editor can inject malicious SWF files.
CVE-2019-7874 1 Magento 1 Magento 2019-08-07 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.
CVE-2019-7934 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit newsletter templates to inject malicious javascript.
CVE-2019-7875 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to newsletter templates.
CVE-2019-7885 1 Magento 1 Magento 2019-08-07 6.5 MEDIUM 8.8 HIGH
Insufficient input validation in the config builder of the Elastic search module could lead to remote code execution in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This vulnerability could be abused by an authenticated user with the ability to configure the catalog search.
CVE-2019-7881 1 Magento 1 Magento 2019-08-07 3.5 LOW 5.4 MEDIUM
A cross-site scripting mitigation bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user to escalate privileges (admin vs. admin XSS attack).
CVE-2018-20951 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
CVE-2019-7935 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content page titles to inject malicious javascript.
CVE-2018-20950 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
CVE-2018-20949 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
CVE-2019-7887 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A reflected cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 when the feature that adds a secret key to the Admin URL is disabled.
CVE-2019-7938 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify catalog price rules to inject malicious javascript.
CVE-2019-7940 1 Magento 1 Magento 2019-08-07 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify store currency options to inject malicious javascript.
CVE-2019-7944 1 Magento 1 Magento 2019-08-07 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to the Return Product comments field can inject malicious javascript.
CVE-2019-7945 1 Magento 1 Magento 2019-08-07 3.5 LOW 5.4 MEDIUM
A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with privileges to modify currency symbols can inject malicious javascript.
CVE-2018-20948 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
CVE-2019-7873 1 Magento 1 Magento 2019-08-07 5.8 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of the store design schedule.
CVE-2018-20946 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2018-20944 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
CVE-2018-11774 1 Apache 1 Virtual Computing Lab 2019-08-07 6.5 MEDIUM 7.2 HIGH
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.
CVE-2018-20940 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
CVE-2018-11773 1 Apache 1 Virtual Computing Lab 2019-08-07 7.5 HIGH 9.8 CRITICAL
Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered appeared to be resistant to a malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.
CVE-2018-20939 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
CVE-2016-10828 1 Cpanel 1 Cpanel 2019-08-07 9.0 HIGH 8.8 HIGH
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
CVE-2018-11772 1 Apache 1 Virtual Computing Lab 2019-08-07 6.5 MEDIUM 7.2 HIGH
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.
CVE-2016-10824 1 Cpanel 1 Cpanel 2019-08-07 9.3 HIGH 9.8 CRITICAL
cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
CVE-2016-10823 1 Cpanel 1 Cpanel 2019-08-07 9.0 HIGH 8.8 HIGH
cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
CVE-2018-20888 1 Cpanel 1 Cpanel 2019-08-07 4.9 MEDIUM 5.5 MEDIUM
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
CVE-2018-20933 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
CVE-2018-20889 1 Cpanel 1 Cpanel 2019-08-07 3.6 LOW 4.4 MEDIUM
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425).
CVE-2018-20894 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443).
CVE-2018-20895 1 Cpanel 1 Cpanel 2019-08-07 6.5 MEDIUM 7.2 HIGH
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).
CVE-2018-20896 1 Cpanel 1 Cpanel 2019-08-07 3.3 LOW 3.9 LOW
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
CVE-2015-9291 1 Cpanel 1 Cpanel 2019-08-07 5.0 MEDIUM 7.5 HIGH
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
CVE-2019-13026 1 Oxid-esales 1 Eshop 2019-08-07 7.5 HIGH 9.8 CRITICAL
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
CVE-2016-10827 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
CVE-2019-14248 1 Nasm 1 Netwide Assembler 2019-08-07 4.3 MEDIUM 5.5 MEDIUM
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
CVE-2019-14468 1 Gnucobol Project 1 Gnucobol 2019-08-07 6.8 MEDIUM 7.8 HIGH
GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code.
CVE-2019-7923 1 Magento 1 Magento 2019-08-07 6.5 MEDIUM 7.2 HIGH
A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by authenticated user with admin privileges to manipulate shipment settings to execute arbitrary code.
CVE-2019-13655 1 Imgix 1 Imgix 2019-08-07 4.3 MEDIUM 6.5 MEDIUM
Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.
CVE-2019-2316 1 Qualcomm 42 Mdm9640, Mdm9640 Firmware, Qcs405 and 39 more 2019-08-07 7.2 HIGH 8.8 HIGH
When computing the digest a local variable is used after going out of scope in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9640, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM660, SDX24
CVE-2019-7930 1 Magento 1 Magento 2019-08-07 9.0 HIGH 7.2 HIGH
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to the import feature can make modifications to a configuration file, resulting in potentially unauthorized removal of file upload restrictions. This can result in arbitrary code execution when a malicious file is then uploaded and executed on the system.
CVE-2016-10822 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
CVE-2018-20935 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
CVE-2017-18473 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
CVE-2017-18471 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
CVE-2017-18472 1 Cpanel 1 Cpanel 2019-08-07 4.3 MEDIUM 6.1 MEDIUM
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
CVE-2017-18481 1 Cpanel 1 Cpanel 2019-08-07 3.5 LOW 5.4 MEDIUM
cPanel before 62.0.4 allows stored XSS in the WHM Account Suspension List interface (SEC-211).
CVE-2018-11780 4 Apache, Canonical, Debian and 1 more 4 Spamassassin, Ubuntu Linux, Debian Linux and 1 more 2019-08-06 7.5 HIGH 9.8 CRITICAL
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
CVE-2018-11781 4 Apache, Canonical, Debian and 1 more 7 Spamassassin, Ubuntu Linux, Debian Linux and 4 more 2019-08-06 4.6 MEDIUM 7.8 HIGH
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.