|
222341
|
7.2 |
HIGH
Network
|
metinfo
|
metinfo
|
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-16996
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222342
|
4.7 |
MEDIUM
Local
|
linux redhat opensuse
|
linux_kernel enterprise_linux leap
|
In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-16994
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222343
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16745
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222344
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenements.php cid SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16744
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222345
|
8.8 |
HIGH
Network
|
ebrigade
|
ebrigade
|
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16743
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222346
|
8.8 |
HIGH
Network
|
phpbb debian
|
phpbb debian_linux
|
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attac…
|
CWE-352
Origin Validation Error
|
CVE-2019-16993
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222347
|
7.5 |
HIGH
Network
|
keybase
|
keybase
|
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be us…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-16992
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222348
|
7.5 |
HIGH
Network
|
linux opensuse netapp
|
linux_kernel leap aff_a700s_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware h410c_firmware h610s_fir…
|
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-16995
|
2024-11-21 13:31 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222349
|
5.3 |
MEDIUM
Network
|
z.cash
|
zcash
|
Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related to mishandling of exceptions during deserialization of note plaintexts. This aff…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-16930
|
2024-11-21 13:31 |
2019-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222350
|
6.1 |
MEDIUM
Network
|
python debian canonical
|
python debian_linux ubuntu_linux
|
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in L…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16935
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|