|
224971
|
6.7 |
MEDIUM
Local
|
fortinet
|
fortiap-w2 fortiap-s fortiap-u fortiap
|
A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administra…
|
CWE-78
OS Command
|
CVE-2019-15708
|
2024-11-21 13:29 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224972
|
5.9 |
MEDIUM
Network
|
yarnpkg
|
yarn
|
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. Th…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-15608
|
2024-11-21 13:29 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224973
|
9.8 |
CRITICAL
Network
|
kill-port-process_project
|
kill-port-process
|
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
|
CWE-78
OS Command
|
CVE-2019-15609
|
2024-11-21 13:29 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224974
|
3.3 |
LOW
Local
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r354735, and 11.3-RELEASE before 11.3-RELEASE-p6, due to incorrect…
|
CWE-665
Improper Initialization
|
CVE-2019-15875
|
2024-11-21 13:29 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224975
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.
|
NVD-CWE-noinfo
|
CVE-2019-15594
|
2024-11-21 13:29 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224976
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.
|
NVD-CWE-noinfo
|
CVE-2019-15592
|
2024-11-21 13:29 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224977
|
9.8 |
CRITICAL
Network
|
nodejs oracle debian redhat opensuse
|
node.js graalvm communications_cloud_native_core_network_function_cloud_native_environment debian_linux enterprise_linux enterprise_linux_eus leap
|
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
|
NVD-CWE-Other
|
CVE-2019-15606
|
2024-11-21 13:29 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224978
|
9.8 |
CRITICAL
Network
|
nodejs debian fedoraproject opensuse redhat oracle
|
node.js debian_linux fedora leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server software_collections enterprise_linux enterprise_linux_server…
|
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-15605
|
2024-11-21 13:29 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224979
|
7.5 |
HIGH
Network
|
nodejs debian opensuse redhat oracle
|
node.js debian_linux leap software_collections enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux graalvm communications_cloud_na…
|
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15604
|
2024-11-21 13:29 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224980
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportL…
|
NVD-CWE-noinfo
|
CVE-2019-15711
|
2024-11-21 13:29 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|