|
222061
|
6.1 |
MEDIUM
Network
|
jamasoftware
|
connect
|
Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting
|
CWE-79
Cross-site Scripting
|
CVE-2019-19592
|
2024-11-21 13:35 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222062
|
6.7 |
MEDIUM
Local
|
trendmicro
|
antivirus_\+_security_2019 internet_security_2019 maximum_security_2019 premium_security_2019
|
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected…
|
NVD-CWE-noinfo
|
CVE-2019-19697
|
2024-11-21 13:35 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222063
|
5.5 |
MEDIUM
Local
|
trendmicro
|
password_manager
|
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-19696
|
2024-11-21 13:35 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222064
|
6.5 |
MEDIUM
Network
|
gallagher
|
command_centre
|
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated …
|
CWE-862
Missing Authorization
|
CVE-2019-19802
|
2024-11-21 13:35 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222065
|
5.5 |
MEDIUM
Local
|
gallagher
|
command_centre
|
In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an un…
|
NVD-CWE-noinfo
|
CVE-2019-19801
|
2024-11-21 13:35 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222066
|
5.3 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The Add Collaborator allows unlimited data via the author parameter, even if the data does not match anyth…
|
NVD-CWE-noinfo
|
CVE-2019-19859
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222067
|
4.8 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/add_user/UID allows stored XSS via the author parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19858
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222068
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the…
|
CWE-287
Improper Authentication
|
CVE-2019-19857
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222069
|
4.8 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. The User Type on the admin/list_user page allows stored XSS via the type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19856
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222070
|
4.8 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. admin/list_user allows stored XSS via the auth_type parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19855
|
2024-11-21 13:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|