|
218801
|
8.8 |
HIGH
Adjacent
|
dlink
|
dba-1510p_firmware
|
DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.
|
CWE-78
OS Command
|
CVE-2019-6014
|
2024-11-21 13:45 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218802
|
6.6 |
MEDIUM
Physics
|
dlink
|
dba-1510p_firmware
|
DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).
|
CWE-78
OS Command
|
CVE-2019-6013
|
2024-11-21 13:45 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218803
|
7.2 |
HIGH
Network
|
tms-outsource
|
wpdatatables_lite
|
SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2019-6012
|
2024-11-21 13:45 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218804
|
6.1 |
MEDIUM
Network
|
tms-outsource
|
wpdatatables_lite
|
Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6011
|
2024-11-21 13:45 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218805
|
7.8 |
HIGH
Local
|
yokogawa
|
exarqe exasmoc insightsuiteae ga10 exaquantum\/batch exaquantum exaplog exaopc
|
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-6008
|
2024-11-21 13:45 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218806
|
7.8 |
HIGH
Local
|
nvidia
|
geforce_experience
|
NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to…
|
NVD-CWE-noinfo
|
CVE-2019-5702
|
2024-11-21 13:45 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218807
|
7.8 |
HIGH
Local
|
vmware
|
horizon_view_agent workstation
|
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Th…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-5539
|
2024-11-21 13:45 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218808
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commit…
|
NVD-CWE-Other
|
CVE-2019-5487
|
2024-11-21 13:45 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218809
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed…
|
CWE-287
Improper Authentication
|
CVE-2019-5486
|
2024-11-21 13:45 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218810
|
7.5 |
HIGH
Network
|
xmlsoft debian
|
libxslt debian_linux
|
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
|
CWE-787 CWE-843
Out-of-bounds Write Type Confusion
|
CVE-2019-5815
|
2024-11-21 13:45 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|