|
222591
|
8.1 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sen…
|
CWE-611
XXE
|
CVE-2019-14693
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222592
|
6.1 |
MEDIUM
Network
|
verdaccio
|
verdaccio
|
verdaccio before 3.12.0 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14772
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222593
|
9.8 |
CRITICAL
Network
|
open-school
|
open-school
|
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-14754
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222594
|
6.1 |
MEDIUM
Network
|
backdropcms
|
backdrop_core
|
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14770
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222595
|
6.1 |
MEDIUM
Network
|
backdropcms
|
backdrop
|
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a spe…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14769
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222596
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.
|
CWE-667
Improper Locking
|
CVE-2019-14763
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222597
|
6.1 |
MEDIUM
Network
|
osticket
|
osticket
|
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastna…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14750
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222598
|
9.8 |
CRITICAL
Network
|
backdropcms
|
backdrop_cms
|
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded …
|
CWE-20
Improper Input Validation
|
CVE-2019-14771
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222599
|
6.1 |
MEDIUM
Network
|
diaowen
|
dwsurvey
|
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14747
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222600
|
9.8 |
CRITICAL
Network
|
kuaifan
|
kuaifancms
|
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
|
CWE-94
Code Injection
|
CVE-2019-14746
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|