|
223121
|
8.8 |
HIGH
Network
|
fiberhome
|
hg2201t_firmware
|
/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17186
|
2024-11-21 13:31 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223122
|
9.1 |
CRITICAL
Network
|
opendev canonical
|
octavia ubuntu_linux
|
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve …
|
CWE-287
Improper Authentication
|
CVE-2019-17134
|
2024-11-21 13:31 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223123
|
7.5 |
HIGH
Network
|
fiberhome
|
hg2201t_firmware
|
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2019-17187
|
2024-11-21 13:31 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223124
|
5.3 |
MEDIUM
Network
|
centreon
|
centreon_web
|
The token generator in index.php in Centreon Web before 2.8.27 is predictable.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-17105
|
2024-11-21 13:31 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223125
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon_web
|
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack on a user.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17108
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223126
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this…
|
CWE-78
OS Command
|
CVE-2019-17107
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223127
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon_web
|
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-17106
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223128
|
7.5 |
HIGH
Network
|
centreon
|
centreon_vm
|
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2019-17104
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223129
|
7.5 |
HIGH
Network
|
auth0
|
auth0.net
|
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
|
CWE-287
Improper Authentication
|
CVE-2019-16929
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223130
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17262
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|