|
222541
|
9.8 |
CRITICAL
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC vi…
|
CWE-287
Improper Authentication
|
CVE-2019-14985
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222542
|
8.1 |
HIGH
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because the undocumented addons/…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-14984
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222543
|
7.5 |
HIGH
Network
|
istio
|
istio
|
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding …
|
CWE-185
Incorrect Regular Expression
|
CVE-2019-14993
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222544
|
4.8 |
MEDIUM
Network
|
schben
|
framework
|
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14987
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222545
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14982
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222546
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical opensuse
|
imagemagick debian_linux ubuntu_linux leap
|
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a cr…
|
CWE-369
Divide By Zero
|
CVE-2019-14981
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222547
|
6.5 |
MEDIUM
Network
|
imagemagick opensuse
|
imagemagick leap
|
In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafte…
|
CWE-416
Use After Free
|
CVE-2019-14980
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222548
|
6.1 |
MEDIUM
Network
|
icmsdev
|
icms
|
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14976
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222549
|
9.8 |
CRITICAL
Network
|
txjia
|
imcat
|
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
|
CWE-89
SQL Injection
|
CVE-2019-14968
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222550
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14967
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|