|
223231
|
8.8 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all …
|
NVD-CWE-noinfo
|
CVE-2019-13423
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223232
|
6.1 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.
|
CWE-601
Open Redirect
|
CVE-2019-13422
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223233
|
4.9 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
|
CWE-200
Information Exposure
|
CVE-2019-13421
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223234
|
8.4 |
HIGH
Local
|
docker
|
docker
|
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "do…
|
CWE-78
OS Command
|
CVE-2019-13139
|
2024-11-21 13:24 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223235
|
5.4 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13476
|
2024-11-21 13:24 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223236
|
8.8 |
HIGH
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
|
CWE-352
Origin Validation Error
|
CVE-2019-13477
|
2024-11-21 13:24 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223237
|
6.5 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent …
|
NVD-CWE-noinfo
|
CVE-2019-13458
|
2024-11-21 13:24 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223238
|
7.8 |
HIGH
Local
|
extenua
|
silvershield
|
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverShield.config.sqlite with a version containing an a…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13069
|
2024-11-21 13:24 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223239
|
5.9 |
MEDIUM
Network
|
w1.fi fedoraproject canonical debian
|
hostapd fedora ubuntu_linux debian_linux
|
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13377
|
2024-11-21 13:24 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223240
|
5.5 |
MEDIUM
Local
|
stb_vorbis_project debian
|
stb_vorbis debian_linux
|
A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
|
CWE-617
Reachable Assertion
|
CVE-2019-13223
|
2024-11-21 13:24 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|