|
222321
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_protection
|
Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software applic…
|
NVD-CWE-noinfo
|
CVE-2019-18372
|
2024-11-21 13:33 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222322
|
5.3 |
MEDIUM
Network
|
mediawiki
|
abusefilter
|
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, t…
|
CWE-200
Information Exposure
|
CVE-2019-18987
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222323
|
7.5 |
HIGH
Network
|
pimcore
|
pimcore
|
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-18986
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222324
|
9.8 |
CRITICAL
Network
|
pimcore
|
pimcore
|
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-18985
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222325
|
6.1 |
MEDIUM
Network
|
pimcore
|
pimcore
|
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18982
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222326
|
9.8 |
CRITICAL
Network
|
pimcore
|
pimcore
|
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
|
NVD-CWE-noinfo CWE-838
Inappropriate Encoding for Output Context
|
CVE-2019-18981
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222327
|
9.8 |
CRITICAL
Network
|
cyrus fedoraproject debian
|
imap fedora debian_linux
|
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived…
|
NVD-CWE-noinfo
|
CVE-2019-18928
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222328
|
7.5 |
HIGH
Network
|
philips
|
taolight_smart_wi-fi_wiz_connected_led_bulb_9290022656_firmware
|
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its…
|
CWE-306 CWE-311
Missing Authentication for Critical Function Missing Encryption of Sensitive Data
|
CVE-2019-18980
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222329
|
5.3 |
MEDIUM
Network
|
rack-cors_project debian canonical
|
rack-cors debian_linux ubuntu_linux
|
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure …
|
CWE-22
Path Traversal
|
CVE-2019-18978
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222330
|
6.5 |
MEDIUM
Network
|
3xlogic
|
infinias_access_control_firmware
|
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application…
|
CWE-352
Origin Validation Error
|
CVE-2019-18651
|
2024-11-21 13:33 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|