|
212481
|
8.0 |
HIGH
Adjacent
|
gemalto
|
ezio_ds3_server
|
Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
|
CWE-78
OS Command
|
CVE-2019-9156
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212482
|
8.8 |
HIGH
Network
|
primasystems
|
flexair
|
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when configuring the main central controller. These scripts can be immediately execu…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9189
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212483
|
7.5 |
HIGH
Network
|
ikiwiki
|
ikiwiki
|
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-9187
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212484
|
10.0 |
CRITICAL
Network
|
citrix
|
application_delivery_management
|
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-9548
|
2024-11-21 13:51 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212485
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure Permissions.
|
NVD-CWE-noinfo
|
CVE-2019-9485
|
2024-11-21 13:51 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212486
|
5.5 |
MEDIUM
Local
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 3 of 5).
|
CWE-20
Improper Input Validation
|
CVE-2019-9221
|
2024-11-21 13:51 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212487
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 1 of 5).
|
NVD-CWE-noinfo
|
CVE-2019-9218
|
2024-11-21 13:51 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212488
|
7.5 |
HIGH
Network
|
aware
|
knomi
|
The Face authentication component in Aware mobile liveness 2.2.1 sdk 2.2.0 for Knomi allows a Biometrical Liveness authentication bypass via parameter tampering of the /knomi/analyze security_level f…
|
NVD-CWE-noinfo
|
CVE-2019-9196
|
2024-11-21 13:51 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212489
|
9.8 |
CRITICAL
Network
|
gracemedia_media_player_project
|
gracemedia_media_player
|
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
|
CWE-22
Path Traversal
|
CVE-2019-9618
|
2024-11-21 13:51 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212490
|
9.8 |
CRITICAL
Network
|
printerlogic
|
print_management
|
The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenti…
|
NVD-CWE-Other
|
CVE-2019-9505
|
2024-11-21 13:51 |
2019-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|