|
222131
|
5.4 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might in…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19002
|
2024-11-21 13:33 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222132
|
6.5 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the applicat…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-19001
|
2024-11-21 13:33 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222133
|
6.5 |
MEDIUM
Network
|
hitachienergy
|
esoms
|
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sen…
|
CWE-200
Information Exposure
|
CVE-2019-19000
|
2024-11-21 13:33 |
2020-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222134
|
4.3 |
MEDIUM
Network
|
harriscomputer
|
ormed_mis
|
Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an arbitrary empNo value to the ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2Entrie…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-18626
|
2024-11-21 13:33 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222135
|
7.5 |
HIGH
Network
|
bloq
|
univalue
|
UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches an inconsistent state) via input data that triggers an error.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-18936
|
2024-11-21 13:33 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222136
|
6.1 |
MEDIUM
Network
|
squid-cache debian canonical opensuse
|
squid debian_linux ubuntu_linux leap
|
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
|
CWE-74
Injection
|
CVE-2019-18860
|
2024-11-21 13:33 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222137
|
9.8 |
CRITICAL
Network
|
sparkdevnetwork
|
rock_rms
|
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
|
NVD-CWE-noinfo
|
CVE-2019-18641
|
2024-11-21 13:33 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222138
|
7.5 |
HIGH
Network
|
suitecrm
|
suitecrm
|
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-18785
|
2024-11-21 13:33 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222139
|
5.3 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
|
NVD-CWE-Other
|
CVE-2019-18782
|
2024-11-21 13:33 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222140
|
7.8 |
HIGH
Local
|
claranova
|
adaware_antivirus
|
Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into …
|
NVD-CWE-noinfo
|
CVE-2019-18979
|
2024-11-21 13:33 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|