|
222661
|
9.8 |
CRITICAL
Network
|
go-camo_project
|
go-camo
|
A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-14255
|
2024-11-21 13:26 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222662
|
5.4 |
MEDIUM
Network
|
1crm
|
1crm_on-premise
|
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14221
|
2024-11-21 13:26 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222663
|
7.5 |
HIGH
Network
|
eq-3
|
ccu3_firmware
|
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorizati…
|
CWE-20
Improper Input Validation
|
CVE-2019-14474
|
2024-11-21 13:26 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222664
|
9.8 |
CRITICAL
Network
|
yourls
|
yourls
|
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
|
CWE-843
Type Confusion
|
CVE-2019-14537
|
2024-11-21 13:26 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222665
|
8.8 |
HIGH
Network
|
loom
|
loom
|
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same netw…
|
CWE-287
Improper Authentication
|
CVE-2019-14432
|
2024-11-21 13:26 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222666
|
8.8 |
HIGH
Network
|
eq-3
|
ccu2_firmware ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the s…
|
CWE-862
Missing Authorization
|
CVE-2019-14473
|
2024-11-21 13:26 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222667
|
8.8 |
HIGH
Network
|
schben
|
adive
|
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-14347
|
2024-11-21 13:26 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222668
|
8.8 |
HIGH
Network
|
schben
|
adive
|
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
|
CWE-352
Origin Validation Error
|
CVE-2019-14346
|
2024-11-21 13:26 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222669
|
7.5 |
HIGH
Network
|
eq-3
|
ccu2_firmware ccu3_firmware
|
eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in…
|
CWE-862
Missing Authorization
|
CVE-2019-14475
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222670
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the Homepage. An attacker can load malicious JavaScript inside t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14550
|
2024-11-21 13:26 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|