|
222781
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a l…
|
CWE-89
SQL Injection
|
CVE-2019-15105
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222782
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-author…
|
CWE-89
SQL Injection
|
CVE-2019-15104
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222783
|
7.5 |
HIGH
Network
|
linux canonical
|
linux_kernel ubuntu_linux
|
drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15099
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222784
|
4.6 |
MEDIUM
Physics
|
linux canonical opensuse netapp debian
|
linux_kernel ubuntu_linux leap element_software active_iq_performance_analytics_services active_iq_unified_manager data_availability_services debian_linux
|
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15098
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222785
|
6.1 |
MEDIUM
Network
|
diaowen
|
dwsurvey
|
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15095
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222786
|
6.7 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15090
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222787
|
7.8 |
HIGH
Local
|
maxx
|
waves_maxx_audio
|
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15084
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222788
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15081
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222789
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to pri…
|
CWE-77
Command Injection
|
CVE-2019-14944
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222790
|
5.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cl…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14942
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|