|
223011
|
9.8 |
CRITICAL
Network
|
okay-cms
|
okaycms
|
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/Produc…
|
CWE-94
Code Injection
|
CVE-2019-16885
|
2024-11-21 13:31 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223012
|
7.2 |
HIGH
Network
|
inist
|
ezmaster
|
The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance (container) is launched with advanced capabilities (not launched as root)
|
NVD-CWE-noinfo
|
CVE-2019-16767
|
2024-11-21 13:31 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223013
|
8.8 |
HIGH
Network
|
labdigital
|
wagtail-2fa
|
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new de…
|
NVD-CWE-noinfo
|
CVE-2019-16766
|
2024-11-21 13:31 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223014
|
7.8 |
HIGH
Local
|
microsoft
|
codeql
|
If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be execu…
|
NVD-CWE-noinfo
|
CVE-2019-16765
|
2024-11-21 13:31 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223015
|
5.5 |
MEDIUM
Local
|
powauth
|
powassent
|
The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.AuthorizationController` a value is fetched from the user provided params, and `String.to…
|
NVD-CWE-noinfo
|
CVE-2019-16764
|
2024-11-21 13:31 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223016
|
6.1 |
MEDIUM
Network
|
pannellum
|
pannellum
|
In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS attacks. Such an attack would require a user to click on a hot spot to execute a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16763
|
2024-11-21 13:31 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223017
|
7.5 |
HIGH
Network
|
lexmark
|
services_monitor_firmware
|
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host ope…
|
CWE-22
Path Traversal
|
CVE-2019-16758
|
2024-11-21 13:31 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223018
|
7.3 |
HIGH
Local
|
code42
|
code42
|
Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-link library (DLL). The…
|
CWE-426
Untrusted Search Path
|
CVE-2019-16861
|
2024-11-21 13:31 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223019
|
7.3 |
HIGH
Local
|
code42
|
code42
|
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL…
|
CWE-426
Untrusted Search Path
|
CVE-2019-16860
|
2024-11-21 13:31 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223020
|
6.5 |
MEDIUM
Network
|
microfocus
|
operations_agent
|
XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Op…
|
CWE-611
XXE
|
CVE-2019-17085
|
2024-11-21 13:31 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|