|
222341
|
7.5 |
HIGH
Network
|
mediawiki
|
abusefilter
|
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and sum…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-16528
|
2024-11-21 13:30 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222342
|
6.8 |
MEDIUM
Physics
|
hom.ee
|
brain_cube_core
|
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16258
|
2024-11-21 13:30 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222343
|
7.5 |
HIGH
Network
|
phpbb
|
phpbb
|
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
|
CWE-94
Code Injection
|
CVE-2019-16108
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222344
|
9.8 |
CRITICAL
Network
|
netsas
|
enigma_network_management_solution
|
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of sh…
|
CWE-78
OS Command
|
CVE-2019-16072
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222345
|
8.8 |
HIGH
Network
|
netsas
|
enigma_nms
|
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is p…
|
CWE-269
Improper Privilege Management
|
CVE-2019-16071
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222346
|
5.3 |
MEDIUM
Network
|
mediawiki
|
checkuser
|
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
|
NVD-CWE-noinfo
|
CVE-2019-16529
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222347
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or cus…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16375
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222348
|
7.8 |
HIGH
Local
|
hancom
|
hancom_office_neo
|
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
|
CWE-416
Use After Free
|
CVE-2019-16338
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222349
|
7.8 |
HIGH
Local
|
hancom
|
hancom_office_neo
|
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
|
CWE-416
Use After Free
|
CVE-2019-16337
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222350
|
9.8 |
CRITICAL
Network
|
ivanti
|
workspace_control
|
An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid …
|
NVD-CWE-noinfo
|
CVE-2019-16382
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|