|
212641
|
9.8 |
CRITICAL
Network
|
jector
|
fm-k75_firmware
|
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9871
|
2024-11-21 13:52 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212642
|
7.1 |
HIGH
Network
|
logicaldoc
|
logicaldoc
|
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the class PluginRegistry.
|
CWE-22
Path Traversal
|
CVE-2019-9723
|
2024-11-21 13:52 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212643
|
9.8 |
CRITICAL
Network
|
synacor
|
zimbra_collaboration_suite
|
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
|
CWE-611
XXE
|
CVE-2019-9670
|
2024-11-21 13:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212644
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.
|
CWE-200
Information Exposure
|
CVE-2019-9866
|
2024-11-21 13:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212645
|
8.1 |
HIGH
Network
|
windriver
|
vxworks
|
When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9865
|
2024-11-21 13:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212646
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-9732
|
2024-11-21 13:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212647
|
8.8 |
HIGH
Network
|
horde debian
|
groupware debian_linux
|
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image m…
|
CWE-22
Path Traversal
|
CVE-2019-9858
|
2024-11-21 13:52 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212648
|
8.8 |
HIGH
Network
|
westerndigital
|
my_cloud_firmware my_cloud_mirror_gen2_firmware my_cloud_ex2_ultra_firmware my_cloud_ex2100_firmware my_cloud_ex4100_firmware my_cloud_dl2100_firmware my_cloud_dl4100_firmware my…
|
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privi…
|
CWE-59
Link Following
|
CVE-2019-9949
|
2024-11-21 13:52 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212649
|
6.5 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permi…
|
CWE-91
Blind XPath Injection
|
CVE-2019-9892
|
2024-11-21 13:52 |
2019-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212650
|
8.1 |
HIGH
Adjacent
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm system can easily be cloned and used to deactivate …
|
CWE-310
Cryptographic Issues
|
CVE-2019-9861
|
2024-11-21 13:52 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|