|
222651
|
7.7 |
HIGH
Network
|
pydio
|
pydio
|
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-15033
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222652
|
5.3 |
MEDIUM
Network
|
pydio
|
pydio
|
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive inform…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-15032
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222653
|
7.2 |
HIGH
Network
|
atlassian
|
jira_server jira_data_center
|
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before…
|
CWE-94
Code Injection
|
CVE-2019-15001
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222654
|
9.8 |
CRITICAL
Network
|
atlassian
|
bitbucket
|
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the …
|
CWE-78
OS Command
|
CVE-2019-15000
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222655
|
7.5 |
HIGH
Network
|
atlassian
|
jira_service_desk
|
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.16, from version 3.10.0 before version 3.16.8, from version 4.0.0 before version…
|
CWE-22
Path Traversal
|
CVE-2019-14994
|
2024-11-21 13:27 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222656
|
7.8 |
HIGH
Local
|
linux canonical debian fedoraproject opensuse netapp redhat huawei
|
linux_kernel ubuntu_linux debian_linux fedora leap aff_a700s_firmware h410c_firmware h610s_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h50…
|
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migra…
|
-
|
CVE-2019-14835
|
2024-11-21 13:27 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222657
|
4.4 |
MEDIUM
Local
|
freeipa redhat
|
freeipa enterprise_linux
|
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and ca…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-14826
|
2024-11-21 13:27 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222658
|
4.4 |
MEDIUM
Local
|
linux redhat canonical opensuse
|
linux_kernel enterprise_linux ubuntu_linux leap
|
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a trans…
|
CWE-662
Improper Synchronization
|
CVE-2019-15031
|
2024-11-21 13:27 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222659
|
4.4 |
MEDIUM
Local
|
linux redhat canonical opensuse
|
linux_kernel enterprise_linux ubuntu_linux leap
|
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local…
|
CWE-862
Missing Authorization
|
CVE-2019-15030
|
2024-11-21 13:27 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222660
|
5.3 |
MEDIUM
Network
|
easyappointments
|
easy\!appointments
|
Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).
|
NVD-CWE-noinfo
|
CVE-2019-14936
|
2024-11-21 13:27 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|