|
221771
|
8.1 |
HIGH
Network
|
tribalgroup
|
sits\
|
An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its default configuration, related to unencrypted communications sent by the client e…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19127
|
2024-11-21 13:34 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221772
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows a…
|
CWE-78
OS Command
|
CVE-2019-19034
|
2024-11-21 13:34 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221773
|
7.5 |
HIGH
Network
|
xmidt
|
cjwt
|
Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-19324
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221774
|
9.8 |
CRITICAL
Network
|
tellabs
|
optical_line_terminal_1150_firmware
|
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2…
|
CWE-78
OS Command
|
CVE-2019-19148
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221775
|
7.8 |
HIGH
Local
|
redhat
|
openshift
|
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/media…
|
-
|
CVE-2019-19345
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221776
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
|
CWE-78
OS Command
|
CVE-2019-19487
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221777
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon
|
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
|
CWE-22
Path Traversal
|
CVE-2019-19486
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221778
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon
|
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
|
CWE-601
Open Redirect
|
CVE-2019-19484
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221779
|
7.2 |
HIGH
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
|
CWE-89
SQL Injection
|
CVE-2019-19029
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221780
|
4.9 |
MEDIUM
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
|
CWE-89
SQL Injection
|
CVE-2019-19026
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|