Export limit exceeded: 40285 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (40285 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-16909 1 Infosysta 1 In-app \& Desktop Notifications 2024-11-21 4.3 Medium
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects (with authentication as a Jira user, but without authorization for specific projects) via the plugins/servlet/nfj/NotificationSettings URI.
CVE-2019-16907 1 Infosysta 1 In-app \& Desktop Notifications 2024-11-21 5.3 Medium
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all valid Jira usernames without authentication/authorization via the plugins/servlet/nfj/UserFilter?searchQuery=@ URI.
CVE-2019-16906 1 Infosysta 1 In-app \& Desktop Notifications 2024-11-21 7.5 High
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servlet/nfj/PushNotification?username= with a modified username, a different user's notifications can be read without authentication/authorization. These notifications are then no longer displayed to the normal user.
CVE-2019-16894 1 Inoideas 1 Inoerp 2024-11-21 9.8 Critical
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
CVE-2019-16884 6 Canonical, Docker, Fedoraproject and 3 more 12 Ubuntu Linux, Docker, Fedora and 9 more 2024-11-21 7.5 High
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
CVE-2019-16866 2 Canonical, Nlnetlabs 2 Ubuntu Linux, Unbound 2024-11-21 7.5 High
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
CVE-2019-16745 1 Ebrigade 1 Ebrigade 2024-11-21 8.8 High
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
CVE-2019-16744 1 Ebrigade 1 Ebrigade 2024-11-21 8.8 High
eBrigade before 5.0 has evenements.php cid SQL Injection.
CVE-2019-16743 1 Ebrigade 1 Ebrigade 2024-11-21 8.8 High
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
CVE-2019-16698 1 Dkd 1 Direct Mail 2024-11-21 4.3 Medium
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.
CVE-2019-16696 1 Phpipam 1 Phpipam 2024-11-21 9.8 Critical
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2019-16695 1 Phpipam 1 Phpipam 2024-11-21 9.8 Critical
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16694 1 Phpipam 1 Phpipam 2024-11-21 9.8 Critical
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
CVE-2019-16692 1 Phpipam 1 Phpipam 2024-11-21 9.8 Critical
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
CVE-2019-16682 1 Url Redirect Project 1 Url Redirect 2024-11-21 7.3 High
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.
CVE-2019-16651 1 Virginmedia 2 Super Hub 3, Super Hub 3 Firmware 2024-11-21 5.3 Medium
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN IP address of a user (if they are using certain VPN implementations, this would decloak them).
CVE-2019-16644 1 Tuzicms 1 Tuzicms 2024-11-21 9.8 Critical
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
CVE-2019-16642 1 Yejiao 1 Tuzicms 2024-11-21 9.8 Critical
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
CVE-2019-16576 1 Jenkins 1 Alauda Kubernetes Support 2024-11-21 6.5 Medium
A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.
CVE-2019-16574 1 Jenkins 1 Alauda Devops Pipeline 2024-11-21 6.5 Medium
A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.