|
211091
|
9.8 |
CRITICAL
Network
|
tongda2000
|
office_anywhere
|
An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9759
|
2024-11-21 13:52 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211092
|
7.5 |
HIGH
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2019-9922
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211093
|
6.5 |
MEDIUM
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-9921
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211094
|
8.8 |
HIGH
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.
|
NVD-CWE-noinfo
|
CVE-2019-9920
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211095
|
5.4 |
MEDIUM
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the mess…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9919
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211096
|
9.1 |
CRITICAL
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Sta…
|
CWE-89
SQL Injection
|
CVE-2019-9918
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211097
|
6.8 |
MEDIUM
Physics
|
symantec
|
norton_core_firmware
|
Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that has the potential of allowing an individual to execute arbitrary commands or c…
|
NVD-CWE-noinfo
|
CVE-2019-9695
|
2024-11-21 13:52 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211098
|
6.5 |
MEDIUM
Network
|
amazon_affiliate_store_project
|
amazon_affiliate_store
|
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
|
NVD-CWE-noinfo
|
CVE-2019-9864
|
2024-11-21 13:52 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211099
|
9.8 |
CRITICAL
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware secvest_wireless_remote_control_fube50014_firmware secvest_wireless_remote_control_fube50015_firmware
|
Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 and its remote controls FUBE50014 and FUBE50015, an attacker is able to predict v…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-9863
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211100
|
6.5 |
MEDIUM
Adjacent
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware secvest_wireless_remote_control_fube50014_firmware secvest_wireless_remote_control_fube50015_firmware
|
An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote control FUBE50014 or FUBE50015. Because "encrypted signal transmission" is missing, …
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2019-9862
|
2024-11-21 13:52 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|