Search Results (322828 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15611 1 Nextcloud 1 Nextcloud 2024-11-21 4.9 Medium
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications.
CVE-2019-15610 1 Nextcloud 1 Circles 2024-11-21 4.3 Medium
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.
CVE-2019-15609 1 Kill-port-process Project 1 Kill-port-process 2024-11-21 9.8 Critical
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
CVE-2019-15608 1 Yarnpkg 1 Yarn 2024-11-21 5.9 Medium
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
CVE-2019-15607 1 Nodered 1 Node-red 2024-11-21 5.4 Medium
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
CVE-2019-15603 1 Seeftl Project 1 Seeftl 2024-11-21 6.1 Medium
The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing.
CVE-2019-15602 1 Itwork 1 Fileview 2024-11-21 6.1 Medium
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.
CVE-2019-15600 1 Http Server Project 1 Http Server 2024-11-21 7.5 High
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
CVE-2019-15599 1 Tree-kill Project 1 Tree-kill 2024-11-21 9.8 Critical
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
CVE-2019-15598 1 Treekill Project 1 Treekill 2024-11-21 9.8 Critical
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
CVE-2019-15597 1 Node-df Project 1 Node-df 2024-11-21 9.8 Critical
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
CVE-2019-15596 1 Statics-server Project 1 Statics-server 2024-11-21 7.5 High
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
CVE-2019-15595 1 Ui 1 Unifi Video Controller 2024-11-21 8.8 High
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
CVE-2019-15594 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
CVE-2019-15593 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.
CVE-2019-15592 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
CVE-2019-15591 1 Gitlab 1 Gitlab 2024-11-21 6.5 Medium
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
CVE-2019-15590 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration
CVE-2019-15589 1 Gitlab 1 Gitlab 2024-11-21 8.8 High
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.
CVE-2019-15588 1 Sonatype 1 Nexus Repository Manager 2024-11-21 7.2 High
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.