|
222341
|
7.5 |
HIGH
Network
|
snowhaze
|
snowhaze
|
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's …
|
CWE-863
Incorrect Authorization
|
CVE-2019-18949
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222342
|
5.3 |
MEDIUM
Network
|
netease
|
pomelo
|
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-18954
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222343
|
9.8 |
CRITICAL
Network
|
sibsoft
|
xfilesharing
|
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, tha…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-18952
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222344
|
7.5 |
HIGH
Network
|
sibsoft
|
xfilesharing
|
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2019-18951
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222345
|
6.1 |
MEDIUM
Network
|
go-camo_project
|
go-camo
|
Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbitrary content from go-camo's origin.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18923
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222346
|
8.8 |
HIGH
Network
|
fairsketch
|
rise_-_ultimate_project_manager
|
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
|
CWE-352
Origin Validation Error
|
CVE-2019-18884
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222347
|
6.1 |
MEDIUM
Network
|
lavalite
|
lavalite
|
XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18883
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222348
|
7.5 |
HIGH
Network
|
linux
|
acrn
|
The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information…
|
CWE-617
Reachable Assertion
|
CVE-2019-18844
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222349
|
8.6 |
HIGH
Network
|
crun_project fedoraproject
|
crun fedora
|
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in li…
|
CWE-59
Link Following
|
CVE-2019-18837
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222350
|
6.1 |
MEDIUM
Network
|
parallels
|
parallels_plesk_panel
|
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18793
|
2024-11-21 13:33 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|