|
224191
|
6.6 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX App Suite through 7.10.2 has Incorrect Access Control.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16716
|
2024-11-21 13:31 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224192
|
8.8 |
HIGH
Network
|
tiny_file_manager_project
|
tiny_file_manager
|
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16790
|
2024-11-21 13:31 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224193
|
7.8 |
HIGH
Local
|
k7computing
|
k7_ultimate_security
|
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link…
|
CWE-59
Link Following
|
CVE-2019-16896
|
2024-11-21 13:31 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224194
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16781
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224195
|
8.2 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress lead…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16789
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224196
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16780
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224197
|
7.5 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header …
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16786
|
2024-11-21 13:31 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224198
|
7.5 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16785
|
2024-11-21 13:31 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224199
|
9.8 |
CRITICAL
Network
|
beckhoff
|
twincat
|
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-16871
|
2024-11-21 13:31 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224200
|
5.9 |
MEDIUM
Network
|
rack_project fedoraproject opensuse
|
rack fedora leap
|
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack session…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16782
|
2024-11-21 13:31 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|