|
222831
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious JavaScript in the filename. This JavaScript executed when an admin…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14547
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222832
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14546
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222833
|
9.8 |
CRITICAL
Network
|
beardev
|
joomsport
|
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
|
CWE-89
SQL Injection
|
CVE-2019-14348
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222834
|
4.9 |
MEDIUM
Network
|
octopus
|
octopus_deploy octopus_server
|
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration pa…
|
NVD-CWE-noinfo
|
CVE-2019-14525
|
2024-11-21 13:26 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222835
|
7.5 |
HIGH
Network
|
emca
|
energy_logserver
|
The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of file to any location on the server via path traversal in the filename parameter.
|
CWE-22
Path Traversal
|
CVE-2019-14521
|
2024-11-21 13:26 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222836
|
9.8 |
CRITICAL
Network
|
daskeyboard
|
das_q_software
|
Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers downlo…
|
CWE-352
Origin Validation Error
|
CVE-2019-14551
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222837
|
9.8 |
CRITICAL
Network
|
gogs
|
gogs
|
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
|
CWE-862
Missing Authorization
|
CVE-2019-14544
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222838
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14541
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222839
|
9.8 |
CRITICAL
Network
|
sleuthkit fedoraproject
|
the_sleuth_kit fedora
|
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
|
CWE-193
Off-by-one Error
|
CVE-2019-14532
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222840
|
9.8 |
CRITICAL
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14531
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|