|
222441
|
8.1 |
HIGH
Network
|
pega
|
pega_platform
|
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform acti…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-16387
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222442
|
8.1 |
HIGH
Network
|
ruby-lang debian opensuse oracle
|
ruby debian_linux leap graalvm
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. …
|
CWE-94
Code Injection
|
CVE-2019-16255
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222443
|
5.3 |
MEDIUM
Network
|
ruby-lang debian
|
ruby debian_linux
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit i…
|
CWE-74
Injection
|
CVE-2019-16254
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222444
|
7.5 |
HIGH
Network
|
ruby-lang debian
|
ruby debian_linux
|
WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBr…
|
CWE-287
Improper Authentication
|
CVE-2019-16201
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222445
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon
|
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16195
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222446
|
6.1 |
MEDIUM
Network
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, including JavaScript running within the KaiOS browser, to view and edit the devic…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16243
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222447
|
6.8 |
MEDIUM
Physics
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse …
|
CWE-78
OS Command
|
CVE-2019-16242
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222448
|
6.8 |
MEDIUM
Physics
|
alcatelmobile
|
cingular_flip_2_firmware
|
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the /data/local/tmp/ directory. The System application that implements the lock sc…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-16241
|
2024-11-21 13:30 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222449
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro
|
In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose …
|
NVD-CWE-noinfo
|
CVE-2019-16287
|
2024-11-21 13:30 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222450
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro_linux
|
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute a…
|
CWE-287
Improper Authentication
|
CVE-2019-16286
|
2024-11-21 13:30 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|