|
222261
|
5.9 |
MEDIUM
Network
|
st
|
st33tphf2espi_firmware st33tphf2ei2c_firmware st33tphf20spi_firmware st33tphf20i2c_firmware
|
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka…
|
CWE-327 CWE-203
Use of a Broken or Risky Cryptographic Algorithm Information Exposure Through Discrepancy
|
CVE-2019-16863
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222262
|
5.3 |
MEDIUM
Network
|
enghouse
|
web_chat
|
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2019-16951
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222263
|
6.1 |
MEDIUM
Network
|
enghouse
|
web_chat
|
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16950
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222264
|
6.5 |
MEDIUM
Network
|
enghouse
|
web_chat
|
An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email address specified at the beginning of the chat (where the us…
|
CWE-20
Improper Input Validation
|
CVE-2019-16949
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222265
|
9.8 |
CRITICAL
Network
|
enghouse
|
web_chat
|
An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-16948
|
2024-11-21 13:31 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222266
|
8.8 |
HIGH
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-17237
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222267
|
6.1 |
MEDIUM
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17236
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222268
|
5.3 |
MEDIUM
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17235
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222269
|
7.5 |
HIGH
Network
|
getigniteup
|
igniteup
|
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary file deletion.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17234
|
2024-11-21 13:31 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222270
|
6.1 |
MEDIUM
Network
|
intelbras
|
wrn_150_firmware
|
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the confi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17222
|
2024-11-21 13:31 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|