|
223601
|
7.5 |
HIGH
Network
|
intercom
|
intercom
|
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
|
CWE-200
Information Exposure
|
CVE-2019-14365
|
2024-11-21 13:26 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223602
|
4.6 |
MEDIUM
Physics
|
hyundai-pay
|
hk-1000
|
On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allow…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14360
|
2024-11-21 13:26 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223603
|
4.6 |
MEDIUM
Physics
|
archos
|
safe-t
|
On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partia…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14358
|
2024-11-21 13:26 |
2019-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223604
|
5.3 |
MEDIUM
Network
|
coinkite
|
coldcard_mk1_firmware coldcard_mk2_firmware
|
On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14356
|
2024-11-21 13:26 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223605
|
9.8 |
CRITICAL
Network
|
repetier-server
|
repetier-server
|
A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation of a user controlled XML file at an unintended location. When…
|
CWE-22
Path Traversal
|
CVE-2019-14450
|
2024-11-21 13:26 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223606
|
9.8 |
CRITICAL
Network
|
repetier-server
|
repetier-server
|
RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14451
|
2024-11-21 13:26 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223607
|
6.5 |
MEDIUM
Network
|
xnat
|
xnat
|
WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
|
CWE-611
XXE
|
CVE-2019-14276
|
2024-11-21 13:26 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223608
|
8.8 |
HIGH
Network
|
sudo_project fedoraproject debian opensuse canonical netapp redhat
|
sudo fedora debian_linux leap ubuntu_linux element_software_management_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus enterprise_linux_wo…
|
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a cra…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-14287
|
2024-11-21 13:26 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223609
|
6.5 |
MEDIUM
Network
|
eq-3
|
cux-daemon ccu2_firmware
|
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTT…
|
CWE-22
Path Traversal
|
CVE-2019-14424
|
2024-11-21 13:26 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223610
|
8.8 |
HIGH
Network
|
eq-3
|
cux-daemon ccu2_firmware
|
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remo…
|
CWE-78
OS Command
|
CVE-2019-14423
|
2024-11-21 13:26 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|