|
224121
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12950
|
2024-11-21 13:23 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224122
|
9.8 |
CRITICAL
Network
|
elmelectronics
|
elm27_firmware
|
A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-12797
|
2024-11-21 13:23 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224123
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_protection
|
Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege es…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12750
|
2024-11-21 13:23 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224124
|
8.3 |
HIGH
Network
|
polycom
|
unified_communications_software united_communications_software
|
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote…
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2019-12948
|
2024-11-21 13:23 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224125
|
5.3 |
MEDIUM
Network
|
humhub
|
social_network_kit
|
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-12743
|
2024-11-21 13:23 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224126
|
5.5 |
MEDIUM
Local
|
sweetscape
|
010_editor
|
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-12552
|
2024-11-21 13:23 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224127
|
5.5 |
MEDIUM
Local
|
sweetscape
|
010_editor
|
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary mem…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12551
|
2024-11-21 13:23 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224128
|
8.8 |
HIGH
Network
|
wp-code-highlightjs_project
|
wp-code-highlightjs
|
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hlj…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-12934
|
2024-11-21 13:23 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224129
|
9.8 |
CRITICAL
Network
|
proftpd fedoraproject debian siemens
|
proftpd fedora debian_linux simatic_cp_1543-1_firmware
|
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-12815
|
2024-11-21 13:23 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224130
|
9.8 |
CRITICAL
Network
|
zeroshell
|
zeroshell
|
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exp…
|
CWE-78
OS Command
|
CVE-2019-12725
|
2024-11-21 13:23 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|