|
222431
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has Incorrect Access Control.
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2019-15932
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222432
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
|
CWE-22
Path Traversal
|
CVE-2019-15931
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222433
|
4.3 |
MEDIUM
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp allows Clickjacking.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-15930
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222434
|
9.6 |
CRITICAL
Adjacent
|
thinkparq
|
beegfs
|
beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).
|
CWE-287
Improper Authentication
|
CVE-2019-15897
|
2024-11-21 13:29 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222435
|
7.8 |
HIGH
Local
|
copadata
|
zenon
|
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-15638
|
2024-11-21 13:29 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222436
|
6.7 |
MEDIUM
Local
|
kaspersky
|
total_security secure_connection kaspersky_internet_security security_cloud
|
Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-15689
|
2024-11-21 13:29 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222437
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus_\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mech…
|
CWE-426
Untrusted Search Path
|
CVE-2019-15628
|
2024-11-21 13:29 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222438
|
9.8 |
CRITICAL
Network
|
mulesoft
|
mule_runtime api_gateway
|
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2019-15631
|
2024-11-21 13:29 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222439
|
7.5 |
HIGH
Network
|
fortinet
|
fortios
|
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by …
|
CWE-20
Improper Input Validation
|
CVE-2019-15705
|
2024-11-21 13:29 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222440
|
6.5 |
MEDIUM
Network
|
ruby-lang canonical
|
ruby ubuntu_linux
|
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
|
NVD-CWE-noinfo
|
CVE-2019-15845
|
2024-11-21 13:29 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|