|
222641
|
6.5 |
MEDIUM
Network
|
centos-webpanel
|
centos_web_panel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14246
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222642
|
6.5 |
MEDIUM
Network
|
centos-webpanel
|
centos_web_panel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14245
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222643
|
5.3 |
MEDIUM
Network
|
youphptube
|
youphptube
|
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-14430
|
2024-11-21 13:26 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222644
|
8.8 |
HIGH
Network
|
tortoisesvn
|
tortoisesvn
|
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from …
|
NVD-CWE-noinfo
|
CVE-2019-14422
|
2024-11-21 13:26 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222645
|
5.4 |
MEDIUM
Network
|
modx
|
evolution_cms
|
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14518
|
2024-11-21 13:26 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222646
|
6.1 |
MEDIUM
Network
|
webstudio
|
ultimate_loan_manager
|
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14427
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222647
|
9.8 |
CRITICAL
Network
|
netgear
|
mr1100_firmware
|
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.
|
CWE-78
OS Command
|
CVE-2019-14527
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222648
|
8.1 |
HIGH
Network
|
netgear
|
mr1100_firmware
|
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefor…
|
CWE-352
Origin Validation Error
|
CVE-2019-14526
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222649
|
8.8 |
HIGH
Network
|
wp_svg_icons_project
|
wp_svg_icons
|
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads…
|
CWE-352
Origin Validation Error
|
CVE-2019-14216
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222650
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. …
|
CWE-22
Path Traversal
|
CVE-2019-14530
|
2024-11-21 13:26 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|