|
211231
|
6.1 |
MEDIUM
Network
|
stackstorm
|
stackstorm
|
In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9580
|
2024-11-21 13:51 |
2019-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211232
|
7.0 |
HIGH
Local
|
cyberark
|
endpoint_privilege_manager
|
A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9627
|
2024-11-21 13:51 |
2019-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211233
|
6.5 |
MEDIUM
Network
|
chshcms
|
cscms
|
An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.
|
CWE-352
Origin Validation Error
|
CVE-2019-9598
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211234
|
8.8 |
HIGH
Network
|
boltcms
|
bolt
|
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9185
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211235
|
9.8 |
CRITICAL
Network
|
motorola
|
m2_firmware c1_firmware
|
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root …
|
CWE-78
OS Command
|
CVE-2019-9121
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211236
|
9.8 |
CRITICAL
Network
|
motorola
|
m2_firmware c1_firmware
|
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root …
|
CWE-78
OS Command
|
CVE-2019-9120
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211237
|
9.8 |
CRITICAL
Network
|
motorola
|
m2_firmware c1_firmware
|
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root …
|
CWE-78
OS Command
|
CVE-2019-9119
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211238
|
9.8 |
CRITICAL
Network
|
motorola
|
m2_firmware c1_firmware
|
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root …
|
CWE-78
OS Command
|
CVE-2019-9118
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211239
|
9.8 |
CRITICAL
Network
|
motorola
|
m2_firmware c1_firmware
|
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root …
|
CWE-78
OS Command
|
CVE-2019-9117
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211240
|
9.8 |
CRITICAL
Network
|
phpshe
|
phpshe
|
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
|
CWE-89
SQL Injection
|
CVE-2019-9626
|
2024-11-21 13:51 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|