|
222101
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
|
CWE-352
Origin Validation Error
|
CVE-2019-18206
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222102
|
6.1 |
MEDIUM
Network
|
zucchetti
|
infobusiness
|
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base6…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18205
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222103
|
8.8 |
HIGH
Network
|
zucchetti
|
infobusiness
|
Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18204
|
2024-11-21 13:32 |
2019-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222104
|
9.8 |
CRITICAL
Network
|
trendmicro
|
officescan apex_one worry-free_business_security
|
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affecte…
|
CWE-22
Path Traversal
|
CVE-2019-18189
|
2024-11-21 13:32 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222105
|
7.5 |
HIGH
Network
|
trendmicro
|
apex_one
|
Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could…
|
CWE-77
Command Injection
|
CVE-2019-18188
|
2024-11-21 13:32 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222106
|
7.5 |
HIGH
Network
|
trendmicro
|
officescan
|
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on …
|
CWE-22
Path Traversal
|
CVE-2019-18187
|
2024-11-21 13:32 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222107
|
8.8 |
HIGH
Network
|
terra-master
|
f2-210_firmware
|
An issue was discovered on TerraMaster FS-210 4.0.19 devices. Normal users can use 1.user.php for privilege elevation.
|
NVD-CWE-noinfo
|
CVE-2019-18195
|
2024-11-21 13:32 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222108
|
6.1 |
MEDIUM
Network
|
corehr
|
core_portal
|
CoreHR Core Portal before 27.0.7 allows stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18221
|
2024-11-21 13:32 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222109
|
7.5 |
HIGH
Network
|
golang debian fedoraproject redhat opensuse arista
|
go debian_linux fedora enterprise_linux developer_tools enterprise_linux_server leap mos eos cloudvision_portal terminattr
|
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client …
|
CWE-436
Interpretation Conflict
|
CVE-2019-17596
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222110
|
6.7 |
MEDIUM
Local
|
teamviewer
|
teamviewer
|
A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 13.2.36216), and 14.6…
|
CWE-426
Untrusted Search Path
|
CVE-2019-18196
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|