|
223401
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-12747
|
2024-11-21 13:23 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223402
|
6.1 |
MEDIUM
Network
|
mailenable
|
mailenable
|
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the …
|
CWE-79
Cross-site Scripting
|
CVE-2019-12927
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223403
|
8.8 |
HIGH
Network
|
mailenable
|
mailenable
|
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in as a user, that tha…
|
CWE-862
Missing Authorization
|
CVE-2019-12926
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223404
|
8.1 |
HIGH
Network
|
mailenable
|
mailenable
|
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible …
|
CWE-22
Path Traversal
|
CVE-2019-12925
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223405
|
9.8 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerab…
|
CWE-611 CWE-311
XXE Missing Encryption of Sensitive Data
|
CVE-2019-12924
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223406
|
6.5 |
MEDIUM
Network
|
mailenable
|
mailenable
|
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF t…
|
CWE-352
Origin Validation Error
|
CVE-2019-12923
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223407
|
6.1 |
MEDIUM
Network
|
wikindx_project
|
wikindx
|
A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12930
|
2024-11-21 13:23 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223408
|
9.8 |
CRITICAL
Network
|
g-u
|
bks_ebk_ethernet-buskoppler_pro_firmware
|
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-12971
|
2024-11-21 13:23 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223409
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-12852
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223410
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
|
NVD-CWE-noinfo
|
CVE-2019-12846
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|