Unknown · CVSS Not scored
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
Published Jul 14, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.
Published Jul 26, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
Published Jul 14, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via the PagingStart parameter.
Published Jul 26, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.
Published Jul 12, 2019 · Updated Aug 4, 2024
Critical · CVSS 9.9
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can create a new script with an editor. It is possible to execute commands on the server using the _execute() function.
Published Jul 14, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.
Published Jul 31, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XSS exists in Ping Identity Agentless Integration Kit before 1.5.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter to the /register URI, because the jQuery prepend() method is used.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
Published Jul 18, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.
Published Jul 12, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
Published Jul 23, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
Published Jul 12, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially crafted URL. Based on the available command-line arguments of the software, one can simply inject -exec to execute arbitrary commands. The additional arguments -hideterm and -exitwhendone in the payload make the attack less visible.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
Published Jul 29, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
Published Jul 25, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
Published Jul 11, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.
Published Jul 8, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_submit in modules/system/system.module.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
Published Jul 16, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.
Published Jul 8, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
Published Jul 8, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.
Published Jul 8, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could exploit the vulnerable function in order to prepare an XSS payload to send to the product's clients.
Published Jul 17, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php.
Published Jul 8, 2019 · Updated Aug 4, 2024