|
218771
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
|
NVD-CWE-Other CWE-269
Improper Privilege Management
|
CVE-2019-5472
|
2024-11-21 13:45 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218772
|
6.1 |
MEDIUM
Network
|
f-revocrm
|
f-revocrm
|
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6036
|
2024-11-21 13:45 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218773
|
5.5 |
MEDIUM
Local
|
fortinet
|
fortios
|
Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the k…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-5593
|
2024-11-21 13:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218774
|
7.1 |
HIGH
Local
|
rapid7
|
appspider
|
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijack…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-5647
|
2024-11-21 13:45 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218775
|
7.5 |
HIGH
Network
|
anglers-net
|
cgi_an-anlyzer
|
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5990
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218776
|
6.1 |
MEDIUM
Network
|
anglers-net
|
cgi_an-anlyzer
|
DOM-based cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Analysis Ob…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5989
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218777
|
6.1 |
MEDIUM
Network
|
anglers-net
|
cgi_an-anlyzer
|
Stored cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Management Pag…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5988
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218778
|
8.8 |
HIGH
Network
|
anglers-net
|
cgi_an-anlyzer
|
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.
|
CWE-78
OS Command
|
CVE-2019-5987
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218779
|
6.5 |
MEDIUM
Network
|
google opensuse
|
chrome leap backports_sle
|
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5846
|
2024-11-21 13:45 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218780
|
6.5 |
MEDIUM
Network
|
google opensuse
|
chrome leap backports_sle
|
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5845
|
2024-11-21 13:45 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|