|
222671
|
5.4 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access and delete DNS records of a victim's account via an attacker account.
|
NVD-CWE-noinfo
|
CVE-2019-14726
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222672
|
4.3 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a victim's e-mail account via an attacker account.
|
NVD-CWE-noinfo
|
CVE-2019-14723
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222673
|
4.3 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.
|
NVD-CWE-noinfo
|
CVE-2019-14722
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222674
|
6.5 |
MEDIUM
Network
|
control-webpanel
|
webpanel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin via an attacker account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14721
|
2024-11-21 13:27 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222675
|
9.8 |
CRITICAL
Network
|
artifex redhat fedoraproject opensuse debian
|
ghostscript enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server openshift_container_platform enterprise_linux_server_eus enterprise_lin…
|
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A…
|
CWE-863
Incorrect Authorization
|
CVE-2019-14813
|
2024-11-21 13:27 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222676
|
8.8 |
HIGH
Network
|
fusionpbx
|
fusionpbx
|
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To …
|
CWE-78
OS Command
|
CVE-2019-15029
|
2024-11-21 13:27 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222677
|
7.8 |
HIGH
Local
|
artifex redhat opensuse fedoraproject debian
|
ghostscript openshift_container_platform leap fedora debian_linux
|
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrict…
|
CWE-863
Incorrect Authorization
|
CVE-2019-14817
|
2024-11-21 13:27 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222678
|
7.8 |
HIGH
Local
|
artifex redhat fedoraproject opensuse debian
|
ghostscript openshift_container_platform fedora leap debian_linux
|
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restriction…
|
CWE-863
Incorrect Authorization
|
CVE-2019-14811
|
2024-11-21 13:27 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222679
|
7.5 |
HIGH
Network
|
grafana
|
grafana
|
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15043
|
2024-11-21 13:27 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222680
|
7.5 |
HIGH
Network
|
memcached
|
memcached
|
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15026
|
2024-11-21 13:27 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|