|
223331
|
4.3 |
MEDIUM
Network
|
cisco
|
enterprise_network_functions_virtualization_infrastructure
|
A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enum…
|
CWE-538
File and Directory Information Exposure
|
CVE-2019-12623
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223332
|
5.5 |
MEDIUM
Local
|
cisco
|
telepresence_codec_c40_firmware telepresence_codec_c60_firmware telepresence_codec_c90_firmware roomos
|
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permis…
|
NVD-CWE-Other
|
CVE-2019-12622
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223333
|
7.4 |
HIGH
Network
|
cisco
|
hyperflex_hx220c_m5_firmware hyperflex_hx240c_m5_firmware hyperflex_hx220c_af_m5_firmware hyperflex_hx240c_af_m5_firmware hyperflex_hx220c_edge_m5_firmware
|
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-12621
|
2024-11-21 13:23 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223334
|
6.5 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their sess…
|
CWE-200
Information Exposure
|
CVE-2019-12746
|
2024-11-21 13:23 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223335
|
7.0 |
HIGH
Local
|
sailpoint
|
desktop_password_reset
|
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System.…
|
CWE-269
Improper Privilege Management
|
CVE-2019-12889
|
2024-11-21 13:23 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223336
|
8.8 |
HIGH
Network
|
vestacp
|
control_panel
|
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
|
CWE-78
OS Command
|
CVE-2019-12792
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223337
|
8.8 |
HIGH
Network
|
vestacp
|
control_panel
|
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
|
CWE-22
Path Traversal
|
CVE-2019-12791
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223338
|
8.8 |
HIGH
Network
|
yes24
|
viewer_activex
|
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attackers to download and execute arbitrary files by setting the arguments to the Acti…
|
NVD-CWE-noinfo
|
CVE-2019-12809
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223339
|
7.5 |
HIGH
Network
|
squid-cache debian fedoraproject canonical opensuse
|
squid debian_linux fedora ubuntu_linux leap
|
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpecte…
|
NVD-CWE-noinfo
|
CVE-2019-12854
|
2024-11-21 13:23 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223340
|
7.8 |
HIGH
Local
|
estsoft
|
altools
|
ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can overwrite an executable that is launched as a service …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-12808
|
2024-11-21 13:23 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|