|
221711
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
|
CWE-89
SQL Injection
|
CVE-2019-19499
|
2024-11-21 13:34 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221712
|
7.8 |
HIGH
Local
|
wowza
|
streaming_engine
|
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19455
|
2024-11-21 13:34 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221713
|
5.4 |
MEDIUM
Network
|
wowza
|
streaming_engine
|
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19453
|
2024-11-21 13:34 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221714
|
5.9 |
MEDIUM
Network
|
silverstripe
|
silverstripe
|
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Origi…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-19326
|
2024-11-21 13:34 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221715
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-19338
|
2024-11-21 13:34 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221716
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affec…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-19417
|
2024-11-21 13:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221717
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affec…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-19416
|
2024-11-21 13:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221718
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affec…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-19415
|
2024-11-21 13:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221719
|
8.8 |
HIGH
Adjacent
|
commax
|
cdp-1020mb_firmware
|
A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbitrary code, because of a using the old version of MySQL.
|
NVD-CWE-noinfo
|
CVE-2019-19163
|
2024-11-21 13:34 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221720
|
7.2 |
HIGH
Network
|
cymiinstaller322_activex_project
|
cymiinstaller322_activex
|
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randoml…
|
CWE-426
Untrusted Search Path
|
CVE-2019-19161
|
2024-11-21 13:34 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|