|
223381
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12542
|
2024-11-21 13:23 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223382
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12541
|
2024-11-21 13:23 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223383
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12538
|
2024-11-21 13:23 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223384
|
8.8 |
HIGH
Network
|
nextcloud
|
extract
|
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile an…
|
CWE-78
OS Command
|
CVE-2019-12739
|
2024-11-21 13:23 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223385
|
8.6 |
HIGH
Local
|
vim neovim
|
vim neovim
|
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert…
|
CWE-78
OS Command
|
CVE-2019-12735
|
2024-11-21 13:23 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223386
|
6.5 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF attack against a phpMyAdmin user. The attacker can trick the user, for instance…
|
CWE-352
Origin Validation Error
|
CVE-2019-12616
|
2024-11-21 13:23 |
2019-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223387
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-12730
|
2024-11-21 13:23 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223388
|
8.1 |
HIGH
Network
|
grails
|
grails
|
Grails before 3.3.10 used cleartext HTTP to resolve the SDKMan notification service. NOTE: users' apps were not resolving dependencies over cleartext HTTP.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2019-12728
|
2024-11-21 13:23 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223389
|
7.5 |
HIGH
Network
|
ui
|
aircam_firmware
|
On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-streamer binary. The issue can be triggered via malformed RTSP requests that lead t…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12727
|
2024-11-21 13:23 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223390
|
7.5 |
HIGH
Network
|
linux netapp
|
linux_kernel aff_a700s_firmware active_iq_unified_manager solidfire hci_management_node cn1610_firmware h610s_firmware
|
An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-12615
|
2024-11-21 13:23 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|