Total
306384 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-15615 | 1 Nextcloud | 1 Nextcloud | 2024-11-21 | 3.6 LOW | 6.1 MEDIUM |
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. | |||||
CVE-2019-15614 | 1 Nextcloud | 1 Nextcloud | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. | |||||
CVE-2019-15613 | 2 Nextcloud, Opensuse | 2 Nextcloud Server, Backports | 2024-11-21 | 6.0 MEDIUM | 8.0 HIGH |
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes. | |||||
CVE-2019-15612 | 1 Nextcloud | 1 Nextcloud Server | 2024-11-21 | 3.2 LOW | 5.9 MEDIUM |
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. | |||||
CVE-2019-15611 | 1 Nextcloud | 1 Nextcloud | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications. | |||||
CVE-2019-15610 | 1 Nextcloud | 1 Circles | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle. | |||||
CVE-2019-15609 | 1 Kill-port-process Project | 1 Kill-port-process | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. | |||||
CVE-2019-15608 | 1 Yarnpkg | 1 Yarn | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack. | |||||
CVE-2019-15607 | 1 Nodered | 1 Node-red | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. | |||||
CVE-2019-15606 | 5 Debian, Nodejs, Opensuse and 2 more | 7 Debian Linux, Node.js, Leap and 4 more | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | |||||
CVE-2019-15605 | 6 Debian, Fedoraproject, Nodejs and 3 more | 13 Debian Linux, Fedora, Node.js and 10 more | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | |||||
CVE-2019-15604 | 5 Debian, Nodejs, Opensuse and 2 more | 10 Debian Linux, Node.js, Leap and 7 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | |||||
CVE-2019-15603 | 1 Seeftl Project | 1 Seeftl | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing. | |||||
CVE-2019-15602 | 1 Itwork | 1 Fileview | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves. | |||||
CVE-2019-15600 | 1 Http Server Project | 1 Http Server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A Path traversal exists in http_server which allows an attacker to read arbitrary system files. | |||||
CVE-2019-15599 | 1 Tree-kill Project | 1 Tree-kill | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command. | |||||
CVE-2019-15598 | 1 Treekill Project | 1 Treekill | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. | |||||
CVE-2019-15597 | 1 Node-df Project | 1 Node-df | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. | |||||
CVE-2019-15596 | 1 Statics-server Project | 1 Statics-server | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory. | |||||
CVE-2019-15595 | 1 Ui | 1 Unifi Video Controller | 2024-11-21 | 9.3 HIGH | 8.8 HIGH |
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands. |