|
223581
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_express
|
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insuf…
|
CWE-74
Injection
|
CVE-2019-15259
|
2024-11-21 13:28 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223582
|
8.6 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software firepower_threat_defense asa_5505_firmware asa_5510_firmware asa_5512-x_firmware asa_5515-x_firmware asa_5520_firmware asa_5525-x_firmware
|
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthentic…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-15256
|
2024-11-21 13:28 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223583
|
7.5 |
HIGH
Network
|
html-pdf_project
|
html-pdf
|
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-15138
|
2024-11-21 13:28 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223584
|
8.8 |
HIGH
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.
|
CWE-352
Origin Validation Error
|
CVE-2019-15089
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223585
|
9.8 |
CRITICAL
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.
|
NVD-CWE-noinfo
|
CVE-2019-15088
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223586
|
7.2 |
HIGH
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.
|
CWE-94
Code Injection
|
CVE-2019-15087
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223587
|
6.1 |
MEDIUM
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected XSS in the error message.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15086
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223588
|
7.5 |
HIGH
Network
|
prise
|
adas
|
An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
|
CWE-200
Information Exposure
|
CVE-2019-15085
|
2024-11-21 13:28 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223589
|
9.8 |
CRITICAL
Network
|
terrasoft
|
bpm_online_crm_system_sdk
|
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
|
CWE-89
SQL Injection
|
CVE-2019-15301
|
2024-11-21 13:28 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223590
|
9.8 |
CRITICAL
Network
|
code42
|
code42
|
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed. This vulnerabi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15131
|
2024-11-21 13:28 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|