|
213221
|
7.5 |
HIGH
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.1 and earlier allows Information Exposure.
|
NVD-CWE-noinfo
|
CVE-2019-7159
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213222
|
6.1 |
MEDIUM
Network
|
i-doit
|
i-doit
|
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6965
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213223
|
9.8 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-7158
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213224
|
7.5 |
HIGH
Network
|
genieaccess
|
wip3bvaf_firmware
|
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this produ…
|
CWE-22
Path Traversal
|
CVE-2019-7315
|
2024-11-21 13:47 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213225
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr940n_firmware tl-wr941nd_firmware
|
TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispose function. By sending specially crafted ICMP echo request packets, a remote au…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6989
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213226
|
6.5 |
MEDIUM
Network
|
progress
|
sitefinity
|
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-7215
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213227
|
7.8 |
HIGH
Local
|
linksys
|
wrt1900acs_firmware
|
An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (admin-auth) is stored on a victim's computer results in the admin password being…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-7311
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213228
|
6.1 |
MEDIUM
Network
|
qualiteam
|
x-cart
|
X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7220
|
2024-11-21 13:47 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213229
|
7.5 |
HIGH
Network
|
titanhq
|
spamtitan
|
In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. …
|
CWE-74
Injection
|
CVE-2019-6800
|
2024-11-21 13:47 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213230
|
9.8 |
CRITICAL
Network
|
samsung
|
galaxy_s9_firmware
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. …
|
NVD-CWE-noinfo
|
CVE-2019-6742
|
2024-11-21 13:47 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|