|
223391
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12540
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223392
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12539
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223393
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_assetexplorer
|
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12537
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223394
|
9.8 |
CRITICAL
Network
|
schedmd debian fedoraproject opensuse
|
slurm debian_linux fedora leap
|
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-12838
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223395
|
5.5 |
MEDIUM
Local
|
hunesion
|
i-onenet
|
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-12804
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223396
|
9.8 |
CRITICAL
Network
|
hunesion
|
i-onenet
|
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell up…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-12803
|
2024-11-21 13:23 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223397
|
6.1 |
MEDIUM
Network
|
teclib-edition
|
news
|
An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12724
|
2024-11-21 13:23 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223398
|
9.8 |
CRITICAL
Network
|
teclib-edition
|
fields
|
An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.
|
CWE-89
SQL Injection
|
CVE-2019-12723
|
2024-11-21 13:23 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223399
|
8.1 |
HIGH
Network
|
thoughtspot
|
thoughtspot
|
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write access to at least one pinboard to corrupt pinboards…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-12782
|
2024-11-21 13:23 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223400
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12748
|
2024-11-21 13:23 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|