|
219591
|
7.8 |
HIGH
Local
|
dell
|
digital_delivery
|
Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a named pipe that performs binary deserial…
|
NVD-CWE-noinfo
|
CVE-2019-3742
|
2024-11-21 13:42 |
2019-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219592
|
7.8 |
HIGH
Local
|
pivotal apigee newrelic microsoft appdynamics bluemedora contrastsecurity cyberark datadoghq datastax dynatrace forgerock google ibm pagerduty riverbed signalsciences wavefront tibco solace snyk samba splunk sumologic synopsys yugabyte anynines
|
cloud_foundry_notifications cloud_foundry_log_cache_release cloud_foundry_deployment_concourse_tasks cloud_foundry_deployment cloud_foundry_smoke_test cloud_foundry_routing_release …
|
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated mali…
|
CWE-200
Information Exposure
|
CVE-2019-3800
|
2024-11-21 13:42 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219593
|
6.8 |
MEDIUM
Physics
|
dell
|
chengming_3967_firmware chengming_3977_firmware chengming_3980_firmware g3_3579_firmware g3_3779_firmware g5_5587_firmware g5_5590_firmware g7_7588_firmware g7_7590_firmware
|
Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure …
|
NVD-CWE-noinfo
|
CVE-2019-3717
|
2024-11-21 13:42 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219594
|
8.1 |
HIGH
Network
|
gnome redhat
|
evolution-ews enterprise_linux
|
It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting t…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-3890
|
2024-11-21 13:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219595
|
5.4 |
MEDIUM
Network
|
redhat
|
openshift
|
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. V…
|
-
|
CVE-2019-3884
|
2024-11-21 13:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219596
|
7.2 |
HIGH
Network
|
wallaceit
|
wallacepos
|
Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-3960
|
2024-11-21 13:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219597
|
8.8 |
HIGH
Network
|
wallaceit
|
wallacepos
|
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
|
CWE-352
Origin Validation Error
|
CVE-2019-3959
|
2024-11-21 13:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219598
|
5.4 |
MEDIUM
Network
|
wallaceit
|
wallacepos
|
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks via a crafted sales transaction.
|
CWE-79
Cross-site Scripting
|
CVE-2019-3958
|
2024-11-21 13:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219599
|
7.5 |
HIGH
Network
|
amcrest dahua
|
ip2m-841b_firmware ipc-xxbxx dh-ipc-hx863x dh-ipc-hx883x dh-sd4xxxxx dh-sd5xxxxx dh-sd6xxxxx ipc-hx4x3x ipc-hx5x3x nvr2xxx-4ks2 nvr4xxx-4ks2 nvr5xxx-4ks2
|
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.R, Dahua DH-SD4XXXXX…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-3948
|
2024-11-21 13:42 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219600
|
6.2 |
MEDIUM
Physics
|
mcafee
|
data_loss_prevention_endpoint
|
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes b…
|
NVD-CWE-noinfo
|
CVE-2019-3621
|
2024-11-21 13:42 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|