|
223531
|
4.8 |
MEDIUM
Network
|
wso2
|
api_manager
|
An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15108
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223532
|
9.8 |
CRITICAL
Network
|
webmin
|
webmin
|
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
|
CWE-78
OS Command
|
CVE-2019-15107
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223533
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15106
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223534
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a l…
|
CWE-89
SQL Injection
|
CVE-2019-15105
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223535
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-author…
|
CWE-89
SQL Injection
|
CVE-2019-15104
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223536
|
7.5 |
HIGH
Network
|
linux canonical
|
linux_kernel ubuntu_linux
|
drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15099
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223537
|
4.6 |
MEDIUM
Physics
|
linux canonical opensuse netapp debian
|
linux_kernel ubuntu_linux leap element_software active_iq_performance_analytics_services active_iq_unified_manager data_availability_services debian_linux
|
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15098
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223538
|
6.1 |
MEDIUM
Network
|
diaowen
|
dwsurvey
|
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15095
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223539
|
6.7 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15090
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223540
|
7.8 |
HIGH
Local
|
maxx
|
waves_maxx_audio
|
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15084
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|