|
213211
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest user…
|
CWE-862
Missing Authorization
|
CVE-2019-6790
|
2024-11-21 13:47 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213212
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers a…
|
NVD-CWE-noinfo
|
CVE-2019-6787
|
2024-11-21 13:47 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213213
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to …
|
CWE-601
Open Redirect
|
CVE-2019-6781
|
2024-11-21 13:47 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213214
|
5.9 |
MEDIUM
Network
|
citrix
|
sharefile
|
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like g…
|
CWE-287
Improper Authentication
|
CVE-2019-7218
|
2024-11-21 13:47 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213215
|
7.5 |
HIGH
Network
|
citrix
|
sharefile
|
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-7217
|
2024-11-21 13:47 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213216
|
7.5 |
HIGH
Network
|
qnap
|
myqnapcloud
|
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-7181
|
2024-11-21 13:47 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213217
|
9.8 |
CRITICAL
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This po…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-7214
|
2024-11-21 13:47 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213218
|
6.5 |
MEDIUM
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail …
|
CWE-22
Path Traversal
|
CVE-2019-7213
|
2024-11-21 13:47 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213219
|
8.2 |
HIGH
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mai…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-7212
|
2024-11-21 13:47 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213220
|
6.1 |
MEDIUM
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by opening a malicious email or when viewing a malicious file attachment.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7211
|
2024-11-21 13:47 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|