|
213591
|
9.8 |
CRITICAL
Network
|
roxyfileman
|
roxy_fileman
|
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
|
NVD-CWE-noinfo
|
CVE-2019-7174
|
2024-11-21 13:47 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213592
|
8.8 |
HIGH
Network
|
avaya
|
ip_office_contact_center
|
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affect…
|
CWE-89
SQL Injection
|
CVE-2019-7001
|
2024-11-21 13:47 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213593
|
7.5 |
HIGH
Network
|
boldgrid
|
w3_total_cache
|
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
|
NVD-CWE-noinfo
|
CVE-2019-6715
|
2024-11-21 13:47 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213594
|
6.5 |
MEDIUM
Network
|
digium
|
asterisk
|
An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and earlier and 16.1.1 and earlier allows remote authenticated users to crash Asteri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-7251
|
2024-11-21 13:47 |
2019-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213595
|
7.5 |
HIGH
Network
|
z.cash
|
zcash
|
Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven statement, produced ce…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2019-7167
|
2024-11-21 13:47 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213596
|
6.1 |
MEDIUM
Network
|
wpsupportplus
|
wp_support_plus_responsive_ticket_system
|
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7299
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213597
|
5.4 |
MEDIUM
Network
|
invoiceplane
|
invoiceplane
|
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.p…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7223
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213598
|
5.5 |
MEDIUM
Local
|
linux fedoraproject opensuse debian canonical netapp redhat
|
linux_kernel fedora leap debian_linux ubuntu_linux element_software_management_node active_iq_performance_analytics_services enterprise_linux_desktop enterprise_linux_workstat…
|
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
|
NVD-CWE-noinfo
|
CVE-2019-7222
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213599
|
7.8 |
HIGH
Local
|
linux opensuse fedoraproject debian canonical netapp redhat
|
linux_kernel leap fedora debian_linux ubuntu_linux element_software_management_node active_iq_performance_analytics_services enterprise_linux_desktop enterprise_linux_workstat…
|
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
|
CWE-416
Use After Free
|
CVE-2019-7221
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213600
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protec…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-7161
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|