|
223631
|
6.1 |
MEDIUM
Network
|
alfresco
|
alfresco
|
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By man…
|
CWE-601
Open Redirect
|
CVE-2019-14223
|
2024-11-21 13:26 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223632
|
7.2 |
HIGH
Network
|
alfresco
|
alfresco
|
An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to ach…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-14224
|
2024-11-21 13:26 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223633
|
9.8 |
CRITICAL
Network
|
alfresco
|
alfresco
|
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due t…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-14222
|
2024-11-21 13:26 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223634
|
5.5 |
MEDIUM
Local
|
canon
|
print
|
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's m…
|
NVD-CWE-noinfo
|
CVE-2019-14339
|
2024-11-21 13:26 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223635
|
5.3 |
MEDIUM
Network
|
knowage-suite
|
knowage
|
In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
|
NVD-CWE-noinfo
|
CVE-2019-14278
|
2024-11-21 13:26 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223636
|
6.1 |
MEDIUM
Network
|
instagram-php-api_project userproplugin
|
instagram-php-api user_pro
|
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14470
|
2024-11-21 13:26 |
2019-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223637
|
6.5 |
MEDIUM
Adjacent
|
tiktok
|
tiktok
|
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive informatio…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14319
|
2024-11-21 13:26 |
2019-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223638
|
7.5 |
HIGH
Network
|
abus
|
secvest_wireless_alarm_system_fuaa50000_firmware
|
An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to suppress correctly received RF messages sent betw…
|
CWE-310
Cryptographic Issues
|
CVE-2019-14261
|
2024-11-21 13:26 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223639
|
5.5 |
MEDIUM
Local
|
videolan debian
|
vlc_media_player debian_linux
|
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14534
|
2024-11-21 13:26 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223640
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
|
CWE-416
Use After Free
|
CVE-2019-14533
|
2024-11-21 13:26 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|