• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

NVD-CWE-noinfo

CVE-2019-18641

February 26, 2023 by

Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.

CVE-2019-18642

February 26, 2023 by

Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account’s email address, performing a password reset to the new email address could allow an attacker to take over any account.

CVE-2019-18568

February 26, 2023 by

Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.

CVE-2019-18604

February 26, 2023 by

In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

CVE-2019-18608

February 26, 2023 by

Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by adding additional attributes to user-input during the PUT /ajax/cart operation for a checkout, because of getValidDocumentForUpdate in api/server/services/orders/orders.js.

CVE-2019-18448

February 26, 2023 by

An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1278
  • Go to page 1279
  • Go to page 1280
  • Go to page 1281
  • Go to page 1282
  • Interim pages omitted …
  • Go to page 2387
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE