Unknown · CVSS Not scored
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
Published Jun 26, 2019 · Updated Sep 16, 2024
High · CVSS 7.4
IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 159122.
Published Jun 6, 2019 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed version for 6.0.x), and from 6.1.0 before 6.1.2 (the fixed version for 6.1.x) allow remote attackers who have admin permissions to achieve remote code execution on a Bitbucket server instance via path traversal through the Data Center migration tool.
Published Jun 3, 2019 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2.
Published Jun 29, 2020 · Updated Sep 16, 2024
Medium · CVSS 6.5
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.
Published Jun 30, 2019 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
Published Jun 14, 2019 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to upload malicious files. IBM X-Force ID: 156565.
Published Jun 6, 2019 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159648.
Published Jun 27, 2019 · Updated Sep 16, 2024
Medium · CVSS 5.9
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
Published Jun 7, 2019 · Updated Sep 16, 2024
Medium · CVSS 4.8
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Published Jun 18, 2019 · Updated Sep 16, 2024
High · CVSS 7.5
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.
Published Jun 6, 2019 · Updated Sep 16, 2024
Medium · CVSS 6.2
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
Published Jun 14, 2019 · Updated Sep 16, 2024
Medium · CVSS 6.1
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.
Published Jun 25, 2019 · Updated Sep 16, 2024
Medium · CVSS 5.4
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
Published Jun 26, 2019 · Updated Sep 16, 2024
High · CVSS 8.8
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
Published Jun 26, 2019 · Updated Sep 16, 2024
Medium · CVSS 4.3
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: 159416.
Published Jun 26, 2019 · Updated Sep 16, 2024
High · CVSS 8
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
Published Jun 30, 2019 · Updated Sep 16, 2024
Medium · CVSS 5.3
IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restrictions, caused by an error related to insecure HTTP Methods. An attacker could exploit this vulnerability to gain access to the system. IBM X-Force ID: 158881.
Published Jun 17, 2019 · Updated Sep 16, 2024
High · CVSS 7
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.
Published Jun 10, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
Published Jun 13, 2019 · Updated Sep 11, 2024
Medium · CVSS 6.3
A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-143949 was assigned to this vulnerability.
Published Jun 9, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
Published Jun 7, 2021 · Updated Aug 5, 2024
Low · CVSS 3.5
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-135125 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published Jun 9, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
Published Jun 21, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
Published Jun 10, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permissions when deciding whether a user can receive intra-team posts.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consumption) via crafted characters in a SQL LIKE clause to an APIv4 endpoint.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during a role change.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
Published Jun 4, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not require credential re-entry.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastrophic backtracking.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a denial of service (memory consumption) via OpenGraph.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference via FXSYS_wcslen in an Epub file.
Published Jun 4, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJoinPartyRequest has a buffer overflow vulnerability and can be exploited by using a crafted joinParty packet. This can be utilized to conduct arbitrary code execution on a victim's machine.
Published Jun 30, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information during user activation/deactivation.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin/importers/class-wc-product-csv-importer-controller.php.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
Published Jun 19, 2020 · Updated Aug 5, 2024