|
213221
|
9.8 |
CRITICAL
Network
|
canonical
|
snapd ubuntu_linux
|
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This issue affects: Canonical snapd versions prior to 2.37…
|
CWE-863
Incorrect Authorization
|
CVE-2019-7304
|
2024-11-21 13:47 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213222
|
7.5 |
HIGH
Network
|
canonical
|
snapd ubuntu_linux
|
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to ma…
|
NVD-CWE-Other
|
CVE-2019-7303
|
2024-11-21 13:47 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213223
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. A user retains t…
|
CWE-269
Improper Privilege Management
|
CVE-2019-7155
|
2024-11-21 13:47 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213224
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack o…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6796
|
2024-11-21 13:47 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213225
|
6.1 |
MEDIUM
Network
|
zarafa
|
webaccess
|
Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; howeve…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7219
|
2024-11-21 13:47 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213226
|
9.8 |
CRITICAL
Network
|
magento
|
magento
|
An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive data leakage. This issue is fixed in Magento 2.1 prior to 2.1.18…
|
CWE-89
SQL Injection
|
CVE-2019-7139
|
2024-11-21 13:47 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213227
|
9.8 |
CRITICAL
Network
|
roxyfileman
|
roxy_fileman
|
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
|
NVD-CWE-noinfo
|
CVE-2019-7174
|
2024-11-21 13:47 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213228
|
8.8 |
HIGH
Network
|
avaya
|
ip_office_contact_center
|
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affect…
|
CWE-89
SQL Injection
|
CVE-2019-7001
|
2024-11-21 13:47 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213229
|
7.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
|
NVD-CWE-noinfo
|
CVE-2019-6715
|
2024-11-21 13:47 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213230
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asteri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-7251
|
2024-11-21 13:47 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|