Search Results (36514 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15729 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.
CVE-2019-15723 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
CVE-2019-15702 1 Riot-os 1 Riot 2024-11-21 7.5 High
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an unknown zero-length option.
CVE-2019-15691 3 Opensuse, Redhat, Tigervnc 3 Leap, Enterprise Linux, Tigervnc 2024-11-21 7.2 High
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which has been already freed during the process of stack unwinding. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.
CVE-2019-15659 1 Genetechsolutions 1 Pie Register 2024-11-21 N/A
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2019-15658 1 Connect-pg-simple Project 1 Connect-pg-simple 2024-11-21 N/A
connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
CVE-2019-15648 1 Elearningfreak 1 Insert Or Embed Articulate Content 2024-11-21 N/A
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
CVE-2019-15646 1 Carrcommunications 1 Rsvpmaker 2024-11-21 N/A
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
CVE-2019-15622 1 Nextcloud 1 Nextcloud 2024-11-21 2.4 Low
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries.
CVE-2019-15608 1 Yarnpkg 1 Yarn 2024-11-21 5.9 Medium
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
CVE-2019-15576 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
CVE-2019-15574 1 Cipsoft 1 Gesior-aac 2024-11-21 N/A
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
CVE-2019-15573 1 Cipsoft 1 Gesior-aac 2024-11-21 N/A
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
CVE-2019-15572 1 Cipsoft 1 Gesior-aac 2024-11-21 N/A
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
CVE-2019-15571 1 Clonos Project 1 Clonos 2024-11-21 N/A
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
CVE-2019-15570 1 Bedita 1 Bedita 2024-11-21 N/A
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-15569 1 Gov 1 Ccd-data-store-api 2024-11-21 N/A
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.
CVE-2019-15568 1 Idseq 1 Idseq-web 2024-11-21 N/A
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2019-15567 1 Openforis 1 Arena 2024-11-21 N/A
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2019-15566 1 Alfresco 1 Alfresco 2024-11-21 N/A
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.