|
221981
|
2.7 |
LOW
Network
|
netgear
|
gs728tps_firmware
|
On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration panel can access part of the web panel, bypassing authentication.
|
NVD-CWE-noinfo
|
CVE-2019-19964
|
2024-11-21 13:35 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221982
|
4.3 |
MEDIUM
Network
|
arxes-tolina
|
arxes-tolina
|
arxes-tolina 3.0.0 allows User Enumeration.
|
CWE-200
Information Exposure
|
CVE-2019-19677
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221983
|
9.6 |
CRITICAL
Network
|
arxes-tolina
|
arxes-tolina
|
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlz…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-19676
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221984
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date field…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19852
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221985
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19615
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221986
|
5.2 |
MEDIUM
Adjacent
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site…
|
CWE-601
Open Redirect
|
CVE-2019-19613
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221987
|
5.4 |
MEDIUM
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19612
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221988
|
5.4 |
MEDIUM
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
|
CWE-384
Session Fixation
|
CVE-2019-19610
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221989
|
7.2 |
HIGH
Network
|
jfrog
|
artifactory
|
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
|
CWE-862
Missing Authorization
|
CVE-2019-19937
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221990
|
6.5 |
MEDIUM
Network
|
dradisframework
|
dradis
|
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-19946
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|