|
222331
|
9.8 |
CRITICAL
Network
|
openmicroscopy
|
omero.server
|
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
|
NVD-CWE-noinfo
|
CVE-2019-16244
|
2024-11-21 13:30 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222332
|
8.8 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify th…
|
CWE-78
OS Command
|
CVE-2019-16213
|
2024-11-21 13:30 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222333
|
5.3 |
MEDIUM
Network
|
openmicroscopy
|
omero
|
OMERO before 5.6.1 makes the details of each user available to all users.
|
NVD-CWE-noinfo
|
CVE-2019-16245
|
2024-11-21 13:30 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222334
|
5.9 |
MEDIUM
Network
|
nutfind
|
nutfind
|
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16252
|
2024-11-21 13:30 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222335
|
6.1 |
MEDIUM
Network
|
cybelesoft
|
thinfinity_virtualui
|
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must…
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2019-16385
|
2024-11-21 13:30 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222336
|
6.5 |
MEDIUM
Network
|
cybelesoft
|
thinfinity_virtualui
|
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known a…
|
CWE-22
Path Traversal
|
CVE-2019-16384
|
2024-11-21 13:30 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222337
|
5.5 |
MEDIUM
Local
|
fortinet
|
forticlient
|
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local st…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16150
|
2024-11-21 13:30 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222338
|
8.8 |
HIGH
Network
|
tylertech
|
eagle
|
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager U…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16112
|
2024-11-21 13:30 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222339
|
8.8 |
HIGH
Network
|
geniusbytes
|
genius_server
|
An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges.
|
NVD-CWE-noinfo
|
CVE-2019-16653
|
2024-11-21 13:30 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222340
|
7.2 |
HIGH
Network
|
geniusbytes
|
genius_server
|
The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands.
|
NVD-CWE-noinfo
|
CVE-2019-16652
|
2024-11-21 13:30 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|