|
212531
|
9.8 |
CRITICAL
Network
|
sqlite canonical opensuse fedoraproject
|
sqlite ubuntu_linux leap fedora
|
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8457
|
2024-11-21 13:49 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212532
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8346
|
2024-11-21 13:49 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212533
|
8.1 |
HIGH
Network
|
atlassian
|
jira jira_server
|
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to admin…
|
CWE-287
Improper Authentication
|
CVE-2019-8443
|
2024-11-21 13:49 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212534
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_server
|
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access …
|
NVD-CWE-noinfo
|
CVE-2019-8442
|
2024-11-21 13:49 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212535
|
9.8 |
CRITICAL
Network
|
bmc
|
patrol_agent
|
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-8352
|
2024-11-21 13:49 |
2019-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212536
|
5.5 |
MEDIUM
Local
|
falco
|
falco
|
An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine.
|
CWE-416
Use After Free
|
CVE-2019-8339
|
2024-11-21 13:49 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212537
|
5.9 |
MEDIUM
Network
|
gpg-pgp_project
|
gpg-pgp
|
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary em…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-8338
|
2024-11-21 13:49 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212538
|
6.5 |
MEDIUM
Network
|
webiness_inventory_project
|
webiness_inventory
|
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-8404
|
2024-11-21 13:49 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212539
|
6.1 |
MEDIUM
Network
|
qdpm
|
qdpm
|
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8391
|
2024-11-21 13:49 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212540
|
6.1 |
MEDIUM
Network
|
qdpm
|
qdpm
|
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8390
|
2024-11-21 13:49 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|