|
219671
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
|
NVD-CWE-noinfo
|
CVE-2019-20495
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219672
|
3.3 |
LOW
Local
|
cpanel
|
cpanel
|
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-20494
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219673
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
|
CWE-79
Cross-site Scripting
|
CVE-2019-20493
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219674
|
8.8 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
|
NVD-CWE-noinfo
|
CVE-2019-20492
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219675
|
8.8 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
|
NVD-CWE-noinfo
|
CVE-2019-20490
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219676
|
8.8 |
HIGH
Network
|
pydio
|
pydio
|
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-20453
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219677
|
8.8 |
HIGH
Network
|
pydio
|
pydio
|
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user wi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-20452
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219678
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they…
|
CWE-862
Missing Authorization
|
CVE-2019-20407
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219679
|
4.9 |
MEDIUM
Network
|
atlassian
|
application_links
|
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-20105
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219680
|
7.8 |
HIGH
Local
|
gnome linuxmint debian
|
gthumb pix debian_linux
|
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20326
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|