Search Results (323536 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-18376 1 Symantec 1 Management Center 2024-11-21 5.9 Medium
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to perform CSRF attacks against MC.
CVE-2019-18375 1 Broadcom 2 Advanced Secure Gateway, Symantec Proxysg 2024-11-21 6.5 Medium
The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance management interface, can hijack the session of a currently logged-in user and access the management console.
CVE-2019-18374 1 Broadcom 1 Symantec Critical System Protection 2024-11-21 9.8 Critical
Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.
CVE-2019-18373 1 Symantec 1 Norton App Lock 2024-11-21 5.6 Medium
Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.
CVE-2019-18372 1 Symantec 1 Endpoint Protection 2024-11-21 7.8 High
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
CVE-2019-18371 1 Mi 2 Millet Router 3g, Millet Router 3g Firmware 2024-11-21 7.5 High
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by api-third-party/download/extdisks../etc/config/account. With this vulnerability, the attacker can bypass authentication.
CVE-2019-18370 1 Mi 2 Millet Router 3g, Millet Router 3g Firmware 2024-11-21 9.8 Critical
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the application's sh script for testing upload and download speeds reads a URL list from /tmp/speedtest_urls.xml, and there is a command injection vulnerability, as demonstrated by api/xqnetdetect/netspeed.
CVE-2019-18369 1 Jetbrains 1 Youtrack 2024-11-21 5.3 Medium
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
CVE-2019-18368 1 Jetbrains 1 Toolbox 2024-11-21 7.3 High
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
CVE-2019-18367 1 Jetbrains 1 Teamcity 2024-11-21 5.3 Medium
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
CVE-2019-18366 1 Jetbrains 1 Teamcity 2024-11-21 5.3 Medium
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
CVE-2019-18365 1 Jetbrains 1 Teamcity 2024-11-21 4.3 Medium
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
CVE-2019-18364 1 Jetbrains 1 Teamcity 2024-11-21 9.8 Critical
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
CVE-2019-18363 1 Jetbrains 1 Teamcity 2024-11-21 5.3 Medium
In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.
CVE-2019-18362 1 Jetbrains 1 Mps 2024-11-21 5.3 Medium
JetBrains MPS before 2019.2.2 exposed listening ports to the network.
CVE-2019-18361 1 Jetbrains 1 Intellij Idea 2024-11-21 5.3 Medium
JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.
CVE-2019-18360 1 Jetbrains 1 Hub 2024-11-21 5.3 Medium
In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
CVE-2019-18359 1 Glensawyer 1 Mp3gain 2024-11-21 5.5 Medium
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.
CVE-2019-18357 1 Thycotic 1 Secret Server 2024-11-21 6.1 Medium
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
CVE-2019-18356 1 Thycotic 1 Secret Server 2024-11-21 6.1 Medium
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).