|
212451
|
5.5 |
MEDIUM
Local
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnera…
|
-
|
CVE-2019-7819
|
2024-11-21 13:48 |
2023-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212452
|
9.8 |
CRITICAL
Network
|
nukeviet
|
nukeviet
|
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).
|
CWE-89
SQL Injection
|
CVE-2019-7726
|
2024-11-21 13:48 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212453
|
9.8 |
CRITICAL
Network
|
nukeviet
|
nukeviet
|
includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-7725
|
2024-11-21 13:48 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212454
|
8.8 |
HIGH
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
|
CWE-352
Origin Validation Error
|
CVE-2019-7357
|
2024-11-21 13:48 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212455
|
5.4 |
MEDIUM
Network
|
intelliants
|
subrion
|
Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7356
|
2024-11-21 13:48 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212456
|
6.1 |
MEDIUM
Network
|
galileo_cms_project
|
galileo_cms
|
There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.e…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7410
|
2024-11-21 13:48 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212457
|
5.4 |
MEDIUM
Network
|
ifrn
|
sistema_unificado_de_administracao_publica
|
SUAP V2 allows XSS during the update of user information.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7634
|
2024-11-21 13:48 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212458
|
8.8 |
HIGH
Network
|
weberp
|
weberp
|
In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-7755
|
2024-11-21 13:48 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212459
|
7.2 |
HIGH
Network
|
gigabyte
|
app_center
|
An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Speci…
|
CWE-665
Improper Initialization
|
CVE-2019-7630
|
2024-11-21 13:48 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212460
|
9.8 |
CRITICAL
Network
|
johnsoncontrols
|
entrapass
|
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system lev…
|
CWE-20
Improper Input Validation
|
CVE-2019-7589
|
2024-11-21 13:48 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|