|
222611
|
8.8 |
HIGH
Network
|
zingbox
|
inspector
|
A command injection vulnerability exists in the Zingbox Inspector versions 1.286 and earlier, that allows for an authenticated user to execute arbitrary system commands in the CLI.
|
CWE-78
OS Command
|
CVE-2019-15014
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222612
|
6.8 |
MEDIUM
Network
|
renpho
|
renpho
|
An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., e…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14808
|
2024-11-21 13:27 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222613
|
7.8 |
HIGH
Local
|
redhat debian opensuse
|
ansible_engine debian_linux leap backports_sle openstack
|
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin…
|
-
|
CVE-2019-14846
|
2024-11-21 13:27 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222614
|
5.3 |
MEDIUM
Adjacent
|
redhat
|
openshift
|
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this …
|
-
|
CVE-2019-14845
|
2024-11-21 13:27 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222615
|
8.8 |
HIGH
Network
|
yeahlink
|
vp59_firmware t49g_firmware t58v_firmware
|
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../..…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14657
|
2024-11-21 13:27 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222616
|
8.8 |
HIGH
Network
|
yeahlink
|
vp59_firmware t49g_firmware t58v_firmware
|
Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14656
|
2024-11-21 13:27 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222617
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
|
CWE-352
Origin Validation Error
|
CVE-2019-15040
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222618
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The issues were fixed in TeamCity 2019.1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15037
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222619
|
7.2 |
HIGH
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
|
CWE-78
OS Command
|
CVE-2019-15036
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222620
|
5.9 |
MEDIUM
Network
|
jetbrains
|
toolbox
|
JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14959
|
2024-11-21 13:27 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|