|
222431
|
6.1 |
MEDIUM
Network
|
diaowen
|
dwsurvey
|
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15095
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222432
|
6.7 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15090
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222433
|
7.8 |
HIGH
Local
|
maxx
|
waves_maxx_audio
|
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate to SYSTEM.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15084
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222434
|
4.8 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15081
|
2024-11-21 13:28 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222435
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to pri…
|
CWE-77
Command Injection
|
CVE-2019-14944
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222436
|
5.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cl…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14942
|
2024-11-21 13:27 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222437
|
5.3 |
MEDIUM
Network
|
hashicorp
|
nomad
|
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/al…
|
NVD-CWE-noinfo
|
CVE-2019-14802
|
2024-11-21 13:27 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222438
|
8.8 |
HIGH
Network
|
redhat
|
decision_manager process_automation
|
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Cons…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2019-14841
|
2024-11-21 13:27 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222439
|
7.5 |
HIGH
Network
|
redhat
|
decision_manager
|
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.
|
-
|
CVE-2019-14840
|
2024-11-21 13:27 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222440
|
7.5 |
HIGH
Network
|
redhat
|
process_automation descision_manager business-central
|
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
|
CWE-200
Information Exposure
|
CVE-2019-14839
|
2024-11-21 13:27 |
2022-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|