|
223541
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15081
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223542
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to pri…
|
CWE-77
Command Injection
|
CVE-2019-14944
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223543
|
5.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cl…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14942
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223544
|
5.3 |
MEDIUM
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/al…
|
NVD-CWE-noinfo
|
CVE-2019-14802
|
2024-11-21 13:27 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223545
|
8.8 |
HIGH
Network
|
redhat
|
decision_manager process_automation
|
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Cons…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-14841
|
2024-11-21 13:27 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223546
|
7.5 |
HIGH
Network
|
redhat
|
decision_manager
|
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.
|
-
|
CVE-2019-14840
|
2024-11-21 13:27 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223547
|
7.5 |
HIGH
Network
|
redhat
|
process_automation descision_manager business-central
|
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
|
CWE-200
Information Exposure
|
CVE-2019-14839
|
2024-11-21 13:27 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223548
|
8.8 |
HIGH
Network
|
redhat
|
3scale
|
A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct furthe…
|
CWE-352
Origin Validation Error
|
CVE-2019-14836
|
2024-11-21 13:27 |
2021-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223549
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template conte…
|
-
|
CVE-2019-14827
|
2024-11-21 13:27 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223550
|
7.5 |
HIGH
Network
|
lispbx_project
|
lispbx
|
In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-DD.tar without authentication or authorization. The…
|
CWE-863
Incorrect Authorization
|
CVE-2019-15059
|
2024-11-21 13:27 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|