|
222671
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity available to all the users. A malicious user can inject JavaScript in…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14549
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222672
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received through mail. This Article can be formed by an attacker using …
|
CWE-79
Cross-site Scripting
|
CVE-2019-14548
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222673
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14547
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222674
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14546
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222675
|
9.8 |
CRITICAL
Network
|
beardev
|
joomsport
|
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
|
CWE-89
SQL Injection
|
CVE-2019-14348
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222676
|
4.9 |
MEDIUM
Network
|
octopus
|
octopus_deploy octopus_server
|
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration pa…
|
NVD-CWE-noinfo
|
CVE-2019-14525
|
2024-11-21 13:26 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222677
|
7.5 |
HIGH
Network
|
emca
|
energy_logserver
|
The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2019-14521
|
2024-11-21 13:26 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222678
|
9.8 |
CRITICAL
Network
|
daskeyboard
|
das_q_software
|
Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers downlo…
|
CWE-352
Origin Validation Error
|
CVE-2019-14551
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222679
|
9.8 |
CRITICAL
Network
|
gogs
|
gogs
|
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
|
CWE-862
Missing Authorization
|
CVE-2019-14544
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222680
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14541
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|