|
223651
|
7.5 |
HIGH
Network
|
sphinxsearch
|
sphinx
|
Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-14511
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223652
|
7.5 |
HIGH
Network
|
zenoss
|
zenoss
|
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
|
CWE-611
XXE
|
CVE-2019-14258
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223653
|
7.8 |
HIGH
Local
|
zenoss
|
zenoss
|
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-14257
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223654
|
6.5 |
MEDIUM
Network
|
centos-webpanel
|
centos_web_panel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14246
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223655
|
6.5 |
MEDIUM
Network
|
centos-webpanel
|
centos_web_panel
|
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14245
|
2024-11-21 13:26 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223656
|
5.3 |
MEDIUM
Network
|
youphptube
|
youphptube
|
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-14430
|
2024-11-21 13:26 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223657
|
8.8 |
HIGH
Network
|
tortoisesvn
|
tortoisesvn
|
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from …
|
NVD-CWE-noinfo
|
CVE-2019-14422
|
2024-11-21 13:26 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223658
|
5.4 |
MEDIUM
Network
|
modx
|
evolution_cms
|
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14518
|
2024-11-21 13:26 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223659
|
6.1 |
MEDIUM
Network
|
webstudio
|
ultimate_loan_manager
|
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14427
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223660
|
9.8 |
CRITICAL
Network
|
netgear
|
mr1100_firmware
|
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.
|
CWE-78
OS Command
|
CVE-2019-14527
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|