|
212671
|
8.8 |
HIGH
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and ea…
|
CWE-416
Use After Free
|
CVE-2019-7760
|
2024-11-21 13:48 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212672
|
8.8 |
HIGH
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and ea…
|
CWE-416
Use After Free
|
CVE-2019-7759
|
2024-11-21 13:48 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212673
|
6.5 |
MEDIUM
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-7758
|
2024-11-21 13:48 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212674
|
9.1 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab Releases were vulnerable to an authorization issue that allowed users to view …
|
CWE-200
Information Exposure
|
CVE-2019-7353
|
2024-11-21 13:48 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212675
|
9.8 |
CRITICAL
Network
|
mobatek
|
mobaxterm
|
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from…
|
CWE-255
Credentials Management
|
CVE-2019-7690
|
2024-11-21 13:48 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212676
|
5.4 |
MEDIUM
Network
|
mythemeshop
|
launcher
|
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Ti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7411
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212677
|
6.1 |
MEDIUM
Network
|
vegadesign
|
profiledesign_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7409
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212678
|
7.5 |
HIGH
Network
|
lg
|
gamp-7100_firmware gapm-7200_firmware gapm-8000_firmware
|
An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7404
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212679
|
7.7 |
HIGH
Network
|
thehive-project
|
cortex-analyzers
|
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-7652
|
2024-11-21 13:48 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212680
|
9.8 |
CRITICAL
Network
|
cyberark
|
enterprise_password_vault
|
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass a…
|
CWE-611
XXE
|
CVE-2019-7442
|
2024-11-21 13:48 |
2019-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|