|
223501
|
6.1 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
|
CWE-74
Injection
|
CVE-2019-16532
|
2024-11-21 13:30 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223502
|
4.8 |
MEDIUM
Network
|
status301
|
easy_fancybox
|
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16524
|
2024-11-21 13:30 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223503
|
5.3 |
MEDIUM
Network
|
symbiote silverstripe
|
versionedfiles silverstripe
|
In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic …
|
NVD-CWE-noinfo
|
CVE-2019-16409
|
2024-11-21 13:30 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223504
|
7.8 |
HIGH
Local
|
samsung
|
text-to-speech
|
The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate privileges, e.g., to system privileges. The Samsung case ID is 10…
|
NVD-CWE-noinfo
|
CVE-2019-16253
|
2024-11-21 13:30 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223505
|
7.1 |
HIGH
Local
|
hcltech
|
appscan_source
|
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim …
|
CWE-611
XXE
|
CVE-2019-16188
|
2024-11-21 13:30 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223506
|
9.8 |
CRITICAL
Network
|
centreon
|
centreon
|
SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.
|
CWE-89
SQL Injection
|
CVE-2019-16194
|
2024-11-21 13:30 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223507
|
9.8 |
CRITICAL
Network
|
suricata-ids
|
suricata
|
An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16411
|
2024-11-21 13:30 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223508
|
9.1 |
CRITICAL
Network
|
suricata-ids
|
suricata
|
An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16410
|
2024-11-21 13:30 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223509
|
9.4 |
CRITICAL
Network
|
ipswitch
|
moveit_transfer
|
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. …
|
CWE-89
SQL Injection
|
CVE-2019-16383
|
2024-11-21 13:30 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223510
|
9.8 |
CRITICAL
Network
|
makandra
|
consul
|
The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-16377
|
2024-11-21 13:30 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|