Zeros312
CVE-2019-8763 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:34.037000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019080000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8764 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.150000+03:00 | A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting. | MEDIUM | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 0.009820000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8765 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.253000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.069830000 | False | False | False | 0.124 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8766 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:34.357000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.017340000 | False | False | False | 0.006 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8768 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.563000+03:00 | "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items. | MEDIUM | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 0.015940000 | False | False | False | 0.006 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8769 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.663000+03:00 | An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history. | MEDIUM | 4.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N | 0.012510000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8770 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.770000+03:00 | The issue was addressed with improved permissions logic. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to access recent documents. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 0.008910000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2022-42286 | 2023-01-13 05:06:23.110000+03:00 | 2026-06-17 05:04:39.227000+03:00 | DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges. | MEDIUM | 6.00 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H | 0.001880000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8772 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:34.970000+03:00 | An issue existed in the handling of links in encrypted PDFs. This issue was addressed by adding a confirmation prompt. This issue is fixed in macOS Catalina 10.15. An attacker may be able to exfiltrate the contents of an encrypted PDF. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.012220000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8775 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:35.300000+03:00 | The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13.1 and iPadOS 13.1. A person with physical access to an iOS device may be able to access contacts from the lock screen. | LOW | 2.40 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | 0.003050000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8779 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:35.720000+03:00 | A logic issue applied the incorrect restrictions. This issue was addressed by updating the logic to apply the correct restrictions. This issue is fixed in iOS 13.1.1 and iPadOS 13.1.1. Third party app extensions may not receive the correct sandbox restrictions. | CRITICAL | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | 0.014700000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8781 | 2019-12-18 20:33:22+03:00 | 2026-06-17 02:42:36+03:00 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.032530000 | False | False | False | 0.011 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8782 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:36.130000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.018750000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8783 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:36.267000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019680000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8784 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:36.390000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.013460000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8785 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:36.500000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.012830000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8786 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:36.617000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.013610000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8787 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:36.773000+03:00 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.013900000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8788 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.077000+03:00 | An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.012220000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8789 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.183000+03:00 | A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Parsing a maliciously crafted iBooks file may lead to disclosure of user information. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 0.013060000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8791 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.387000+03:00 | An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect. | MEDIUM | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 0.011200000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8792 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.490000+03:00 | An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019300000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8793 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.650000+03:00 | A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 0.002960000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8794 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:37.753000+03:00 | A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 0.009220000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8795 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:37.863000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.013280000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8797 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:38.083000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.013980000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8798 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:38.183000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 0.003440000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8800 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:38.400000+03:00 | A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.009800000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8801 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:38.497000+03:00 | A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.003850000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8802 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:38.593000+03:00 | A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.010360000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8803 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:38.693000+03:00 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials.. | HIGH | 8.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.003310000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8804 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:38.800000+03:00 | An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup. | MEDIUM | 5.70 | CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N | 0.004200000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8805 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:38.907000+03:00 | A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.025670000 | False | False | False | 0.009 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8806 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:39.007000+03:00 | A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.009800000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8807 | 2019-12-18 20:33:23+03:00 | 2026-06-17 02:42:39.107000+03:00 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.012380000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8808 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.210000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.018750000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2026-46130 | 2026-05-28 12:35:45.387000+03:00 | 2026-06-14 20:56:41.180000+03:00 | In the Linux kernel, the following vulnerability has been resolved:
dm-verity-fec: fix reading parity bytes split across blocks (take 3)
fec_decode_bufs() assumes that the parity bytes of the first RS codeword
it decodes are never split across parity blocks.
This assumption is false. Consider v->fec->block_size == 4096 &&
v->fec->roots == 17 && fio->nbufs == 1, for example. In that case, each
call to fec_decode_bufs() consumes v->fec->roots * (fio->nbufs <<
DM_VERITY_FEC_BUF_RS_BITS) = 272 parity bytes.
Considering that the parity data for each message block starts on a
block boundary, the byte alignment in the parity data will iterate
through 272*i mod 4096 until the 3 parity blocks have been consumed. On
the 16th call (i=15), the alignment will be 4080 bytes into the first
block. Only 16 bytes remain in that block, but 17 parity bytes will be
needed. The code reads out-of-bounds from the parity block buffer.
Fortunately this doesn't normally happen, since it can occur only for
certain non-default values of fec_roots *and* when the maximum number of
buffers couldn't be allocated due to low memory. For example with
block_size=4096 only the following cases are affected:
fec_roots=17: nbufs in [1, 3, 5, 15]
fec_roots=19: nbufs in [1, 229]
fec_roots=21: nbufs in [1, 3, 5, 13, 15, 39, 65, 195]
fec_roots=23: nbufs in [1, 89]
Regardless, fix it by refactoring how the parity blocks are read. | 0.001170000 | False | False | False | 0.000 | 2026-06-29 23:03:24.364088+03:00 | |||
CVE-2019-8811 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.440000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.020140000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8812 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.573000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019060000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8813 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.693000+03:00 | A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting. | MEDIUM | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 0.013310000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8814 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.810000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.025630000 | False | False | False | 0.009 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8815 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:39.937000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.023100000 | False | False | False | 0.008 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8816 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.067000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.026040000 | False | False | False | 0.009 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8817 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.197000+03:00 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory. | MEDIUM | 5.50 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 0.008470000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8819 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.300000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019360000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8820 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.423000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.096210000 | False | False | False | 0.134 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8821 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.557000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.020840000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2022-42287 | 2023-01-13 05:07:42.144000+03:00 | 2026-06-17 05:04:39.343000+03:00 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering. | MEDIUM | 6.00 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N | 0.002200000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2022-42288 | 2023-01-13 05:09:02.245000+03:00 | 2026-06-17 05:04:39.460000+03:00 | NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure. | MEDIUM | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 0.004580000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8822 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.687000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.020840000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8823 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:40.813000+03:00 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.019360000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-8849 | 2019-12-18 20:33:24+03:00 | 2026-06-17 02:42:43.523000+03:00 | The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.022120000 | False | False | False | 0.008 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-12415 | 2020-07-09 17:39:37+03:00 | 2026-06-17 02:51:47.520000+03:00 | When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N | 0.012720000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2012-2656 | 2019-12-18 21:16:54+03:00 | 2026-06-16 23:41:49.260000+03:00 | An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.020460000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19844 | 2019-12-18 21:07:11+03:00 | 2026-06-17 02:27:20.267000+03:00 | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.) | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.348100000 | False | False | False | 0.222 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19887 | 2019-12-18 21:40:43+03:00 | 2026-06-17 02:27:23.793000+03:00 | bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H | 0.011400000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19888 | 2019-12-18 21:40:33+03:00 | 2026-06-17 02:27:23.900000+03:00 | jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H | 0.010850000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2022-42289 | 2023-01-13 05:09:44.143000+03:00 | 2026-06-17 05:04:39.580000+03:00 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering. | HIGH | 7.20 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.010150000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2024-53009 | 2025-07-08 15:48:44.614000+03:00 | 2026-06-17 08:08:00.890000+03:00 | Memory corruption while operating the mailbox in Automotive. | MEDIUM | 5.30 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L | 0.000860000 | False | False | False | 0.000 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-6617 | 2020-01-09 01:52:39+03:00 | 2026-06-17 03:23:40.667000+03:00 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.011420000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19889 | 2019-12-18 21:52:52+03:00 | 2026-06-17 02:27:24.007000+03:00 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.010970000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19890 | 2019-12-18 21:53:05+03:00 | 2026-06-17 02:27:24.113000+03:00 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.009870000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2018-1311 | 2019-12-18 03:00:00+03:00 | 2026-06-17 01:50:59.290000+03:00 | The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. | HIGH | 8.10 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.095030000 | False | False | False | 0.033 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-11995 | 2019-12-18 22:46:26+03:00 | 2026-06-17 02:13:58.983000+03:00 | Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.021220000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-16782 | 2019-12-18 22:05:14+03:00 | 2026-06-17 02:22:47.697000+03:00 | There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison. | MEDIUM | 6.30 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N | 0.036870000 | False | False | True | -0.037 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18267 | 2019-12-18 22:37:46+03:00 | 2026-06-17 02:24:43.600000+03:00 | An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 0.015530000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19688 | 2019-12-18 21:30:15+03:00 | 2026-06-17 02:27:05.047000+03:00 | A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.005590000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19689 | 2019-12-18 21:30:16+03:00 | 2026-06-17 02:27:05.780000+03:00 | Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses. | HIGH | 7.80 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.005590000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19690 | 2019-12-18 21:30:16+03:00 | 2026-06-17 02:27:05.880000+03:00 | Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.014580000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-5074 | 2019-12-18 22:30:27+03:00 | 2026-06-17 02:37:05.283000+03:00 | An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.032800000 | False | False | False | 0.011 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-5077 | 2019-12-18 22:53:16+03:00 | 2026-06-17 02:37:05.593000+03:00 | An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability. | CRITICAL | 9.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H | 0.016430000 | False | False | False | 0.006 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2022-42290 | 2023-01-13 05:28:58.208000+03:00 | 2026-06-17 05:04:39.697000+03:00 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering. | HIGH | 7.20 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | 0.010150000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-5081 | 2019-12-18 22:59:36+03:00 | 2026-06-17 02:37:06+03:00 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.045210000 | False | False | False | 0.016 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-7621 | 2019-12-18 22:50:12+03:00 | 2026-06-17 02:40:46.533000+03:00 | Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 0.006520000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15575 | 2019-12-19 00:00:16+03:00 | 2026-06-17 02:20:40.387000+03:00 | A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.024090000 | False | False | False | 0.008 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15576 | 2019-12-19 00:00:08+03:00 | 2026-06-17 02:20:40.507000+03:00 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.018520000 | False | False | False | 0.006 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-12416 | 2020-07-09 17:40:59+03:00 | 2026-06-17 02:51:47.637000+03:00 | A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.013500000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-6618 | 2020-01-09 01:52:28+03:00 | 2026-06-17 03:23:40.793000+03:00 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.011420000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15577 | 2019-12-19 00:00:00+03:00 | 2026-06-17 02:20:40.623000+03:00 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing. | MEDIUM | 4.30 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N | 0.006590000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15580 | 2019-12-18 23:59:15+03:00 | 2026-06-17 02:20:40.980000+03:00 | An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 0.011410000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15589 | 2019-12-19 00:00:39+03:00 | 2026-06-17 02:20:42.043000+03:00 | An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 0.010500000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15591 | 2019-12-18 23:51:27+03:00 | 2026-06-17 02:20:42.273000+03:00 | An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | 0.011490000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15596 | 2019-12-18 23:59:06+03:00 | 2026-06-17 02:20:42.840000+03:00 | A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.015290000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-12417 | 2020-07-09 17:39:37+03:00 | 2026-06-17 02:51:47.747000+03:00 | Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.026880000 | False | False | False | 0.009 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15597 | 2019-12-18 23:58:51+03:00 | 2026-06-17 02:20:42.957000+03:00 | A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.027420000 | False | False | False | 0.010 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15598 | 2019-12-18 23:58:31+03:00 | 2026-06-17 02:20:43.067000+03:00 | A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.027420000 | False | False | False | 0.010 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15599 | 2019-12-18 23:56:56+03:00 | 2026-06-17 02:20:43.177000+03:00 | A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.027420000 | False | False | False | 0.010 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2020-12418 | 2020-07-09 17:19:50+03:00 | 2026-06-17 02:51:47.893000+03:00 | Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | 0.030340000 | False | False | False | 0.011 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-15600 | 2019-12-18 23:56:21+03:00 | 2026-06-17 02:20:43.290000+03:00 | A Path traversal exists in http_server which allows an attacker to read arbitrary system files. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.025090000 | False | False | False | 0.009 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18571 | 2019-12-18 23:50:13.968000+03:00 | 2026-06-17 02:25:06.767000+03:00 | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application. | MEDIUM | 5.40 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 0.005030000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18572 | 2019-12-18 23:50:14.414000+03:00 | 2026-06-17 02:25:07.023000+03:00 | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application. | HIGH | 8.30 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L | 0.019910000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18573 | 2019-12-18 23:50:14.868000+03:00 | 2026-06-17 02:25:07.180000+03:00 | The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session. | HIGH | 8.70 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N | 0.009860000 | False | False | False | 0.003 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18994 | 2019-12-18 23:20:57+03:00 | 2026-06-17 02:25:48.230000+03:00 | Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service. | LOW | 3.90 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L | 0.006050000 | False | False | False | 0.002 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18995 | 2019-12-18 23:19:34+03:00 | 2026-06-17 02:25:56.483000+03:00 | The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting. | MEDIUM | 4.30 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | 0.021330000 | False | False | False | 0.007 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18996 | 2019-12-18 23:24:44+03:00 | 2026-06-17 02:25:57.130000+03:00 | Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context. | HIGH | 7.10 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L | 0.004000000 | False | False | False | 0.001 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-18997 | 2019-12-18 23:22:47+03:00 | 2026-06-17 02:25:57.240000+03:00 | The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access. | MEDIUM | 4.30 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | 0.015220000 | False | False | False | 0.005 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-19724 | 2019-12-18 23:52:24+03:00 | 2026-06-17 02:27:08.630000+03:00 | Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 0.012340000 | False | False | False | 0.004 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-1387 | 2019-12-18 23:11:53+03:00 | 2026-06-17 02:28:30.630000+03:00 | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 0.044260000 | False | False | False | 0.015 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-5073 | 2019-12-18 23:51:48+03:00 | 2026-06-17 02:37:05.177000+03:00 | An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability. | MEDIUM | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 0.016210000 | False | False | False | 0.006 | 2026-06-29 23:03:24.364088+03:00 |
CVE-2019-5075 | 2019-12-18 23:51:51+03:00 | 2026-06-17 02:37:05.383000+03:00 | An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 0.038660000 | False | False | False | 0.014 | 2026-06-29 23:03:24.364088+03:00 |