Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by NVD-CWE-noinfo
Total 22706 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14407 1 Cpanel 1 Cpanel 2021-07-21 4.0 MEDIUM 2.7 LOW
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
CVE-2019-0112 1 Intel 1 Data Center Manager 2021-07-21 2.1 LOW 4.4 MEDIUM
Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable a denial of service via local access.
CVE-2019-0123 1 Intel 294 Core I7-10510u, Core I7-10510u Firmware, Core I7-10510y and 291 more 2021-07-21 7.2 HIGH 7.8 HIGH
Insufficient memory protection in Intel(R) 6th Generation Core Processors and greater, supporting SGX, may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2019-0124 1 Intel 294 Core I7-10510u, Core I7-10510u Firmware, Core I7-10510y and 291 more 2021-07-21 7.2 HIGH 7.8 HIGH
Insufficient memory protection in Intel(R) 6th Generation Core Processors and greater, supporting TXT, may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2019-14404 1 Cpanel 1 Cpanel 2021-07-21 4.9 MEDIUM 5.5 MEDIUM
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
CVE-2019-0139 1 Intel 13 Ethernet 700 Series Software, Ethernet Controller 710-bm1, Ethernet Controller 710-bm1 Firmware and 10 more 2021-07-21 4.6 MEDIUM 6.7 MEDIUM
Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access.
CVE-2019-0142 1 Intel 13 Ethernet 700 Series Software, Ethernet Controller 710-bm1, Ethernet Controller 710-bm1 Firmware and 10 more 2021-07-21 7.2 HIGH 8.2 HIGH
Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2019-14399 1 Cpanel 1 Cpanel 2021-07-21 6.1 MEDIUM 7.1 HIGH
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
CVE-2019-14394 1 Cpanel 1 Cpanel 2021-07-21 2.1 LOW 5.5 MEDIUM
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
CVE-2019-0200 1 Apache 1 Qpid Broker-j 2021-07-21 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending specially crafted commands using AMQP protocol versions below 1.0 (AMQP 0-8, 0-9, 0-91 and 0-10). Users of Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 utilizing AMQP protocols 0-8, 0-9, 0-91, 0-10 must upgrade to Qpid Broker-J versions 7.0.7 or 7.1.1 or later.
CVE-2019-0214 1 Apache 1 Archiva 2021-07-21 5.5 MEDIUM 6.5 MEDIUM
In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the artifact upload mechanism. Existing files can be overwritten, if the archiva run user has appropriate permission on the filesystem for the target file.
CVE-2019-0222 4 Apache, Debian, Netapp and 1 more 8 Activemq, Debian Linux, E-series Santricity Web Services and 5 more 2021-07-21 5.0 MEDIUM 7.5 HIGH
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
CVE-2019-16245 1 Openmicroscopy 1 Omero 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
OMERO before 5.6.1 makes the details of each user available to all users.
CVE-2019-16244 1 Openmicroscopy 1 Omero.server 2021-07-21 7.5 HIGH 9.8 CRITICAL
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CVE-2019-14278 1 Knowage-suite 1 Knowage 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
CVE-2019-14092 1 Qualcomm 16 Mdm9206, Mdm9206 Firmware, Mdm9207c and 13 more 2021-07-21 2.1 LOW 5.5 MEDIUM
System Services exports services without permission protect and can lead to information exposure in Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9207C, MDM9607, Rennell, Saipan, SM8150, SM8250, SXR2130
CVE-2019-13982 1 Rangerstudio 1 Directus 7 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.
CVE-2019-14339 1 Canon 1 Print 2021-07-21 4.3 MEDIUM 5.5 MEDIUM
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.
CVE-2019-13412 1 Hinet 2 Gpon, Gpon Firmware 2021-07-21 5.0 MEDIUM 7.5 HIGH
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
CVE-2019-1338 1 Microsoft 2 Windows 7, Windows Server 2008 2021-07-21 4.3 MEDIUM 5.9 MEDIUM
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'.