|
212211
|
7.5 |
HIGH
Network
|
rdbrck
|
shift
|
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-8932
|
2024-11-21 13:50 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212212
|
7.5 |
HIGH
Network
|
rdbrck
|
shift
|
Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.
|
NVD-CWE-noinfo
|
CVE-2019-8931
|
2024-11-21 13:50 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212213
|
7.8 |
HIGH
Local
|
blackberry
|
qnx_software_development_platform
|
An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.…
|
NVD-CWE-noinfo
|
CVE-2019-8998
|
2024-11-21 13:50 |
2019-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212214
|
6.1 |
MEDIUM
Network
|
apachefriends
|
xampp
|
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8920
|
2024-11-21 13:50 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212215
|
9.8 |
CRITICAL
Network
|
couchbase
|
sync_gateway
|
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions…
|
CWE-89
SQL Injection
|
CVE-2019-9039
|
2024-11-21 13:50 |
2019-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212216
|
6.5 |
MEDIUM
Network
|
digitaldruid
|
hoteldruid
|
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visualizza_contratto.php with invalid arguments (any non-…
|
CWE-20
Improper Input Validation
|
CVE-2019-9085
|
2024-11-21 13:50 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212217
|
9.8 |
CRITICAL
Network
|
digitaldruid
|
hoteldruid
|
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9087
|
2024-11-21 13:50 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212218
|
9.8 |
CRITICAL
Network
|
digitaldruid
|
hoteldruid
|
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9086
|
2024-11-21 13:50 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212219
|
4.9 |
MEDIUM
Network
|
digitaldruid
|
hoteldruid
|
In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 parameter) due to the mishandling of non-numeric values, as demonstrated by the /…
|
CWE-369
Divide By Zero
|
CVE-2019-9084
|
2024-11-21 13:50 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212220
|
9.8 |
CRITICAL
Network
|
saet
|
tebe_small_firmware webapp
|
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to execute or include local .php files, as demonstrated by menu=php://filter/…
|
CWE-22
Path Traversal
|
CVE-2019-9106
|
2024-11-21 13:50 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|