|
222911
|
7.0 |
HIGH
Local
|
redhat
|
openshift
|
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and esc…
|
-
|
CVE-2019-19351
|
2024-11-21 13:34 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222912
|
4.4 |
MEDIUM
Local
|
redhat
|
openshift
|
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials …
|
-
|
CVE-2019-19335
|
2024-11-21 13:34 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222913
|
7.2 |
HIGH
Network
|
sangoma
|
freepbx
|
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
|
NVD-CWE-noinfo
|
CVE-2019-19538
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222914
|
5.4 |
MEDIUM
Network
|
teampasswordmanager
|
team_password_manager
|
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19461
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222915
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
|
CWE-79
Cross-site Scripting
|
CVE-2019-19212
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222916
|
7.4 |
HIGH
Network
|
opcfoundation
|
ua-.netstandard netstandard.opc.ua
|
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle att…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-19135
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222917
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19211
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222918
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19210
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222919
|
7.5 |
HIGH
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-19209
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222920
|
9.8 |
CRITICAL
Network
|
codiad
|
codiad
|
Codiad Web IDE through 2.8.4 allows PHP Code injection.
|
CWE-94
Code Injection
|
CVE-2019-19208
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|