|
223501
|
7.4 |
HIGH
Network
|
twistedmatrix
|
twisted
|
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-12855
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223502
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
|
CWE-78
OS Command
|
CVE-2019-12840
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223503
|
8.8 |
HIGH
Network
|
orangehrm
|
orangehrm
|
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execu…
|
CWE-78
OS Command
|
CVE-2019-12839
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223504
|
9.8 |
CRITICAL
Network
|
leanify_project
|
leanify
|
formats/xml.cpp in Leanify 0.4.3 allows for a controlled out-of-bounds write in xml_memory_writer::write via characters that require escaping.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12835
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223505
|
7.2 |
HIGH
Network
|
mybb
|
mybb
|
In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cac…
|
CWE-20
Improper Input Validation
|
CVE-2019-12831
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223506
|
8.7 |
HIGH
Network
|
mybb
|
mybb
|
In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [video] BBCode persistent XSS to take over any forum account, aka a nested video MyC…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12830
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223507
|
7.5 |
HIGH
Network
|
radare
|
radare2
|
radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, as demonstrated by newstr bu…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12829
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223508
|
8.8 |
HIGH
Network
|
znc
|
znc
|
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.
|
CWE-20
Improper Input Validation
|
CVE-2019-12816
|
2024-11-21 13:23 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223509
|
8.8 |
HIGH
Network
|
ea
|
origin
|
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Orig…
|
CWE-19
Data Processing Errors
|
CVE-2019-12828
|
2024-11-21 13:23 |
2019-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223510
|
7.5 |
HIGH
Network
|
embedthis
|
goahead
|
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as demonstrated by a col…
|
CWE-119 CWE-917
Incorrect Access of Indexable Resource ('Range Error') Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2019-12822
|
2024-11-21 13:23 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|