|
223321
|
6.5 |
MEDIUM
Network
|
cybelesoft
|
thinfinity_virtualui
|
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known a…
|
CWE-22
Path Traversal
|
CVE-2019-16384
|
2024-11-21 13:30 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223322
|
5.5 |
MEDIUM
Local
|
fortinet
|
forticlient
|
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local st…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16150
|
2024-11-21 13:30 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223323
|
8.8 |
HIGH
Network
|
tylertech
|
eagle
|
TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the recorder/ServiceManager?service=tyler.empire.settings.SettingManager U…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16112
|
2024-11-21 13:30 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223324
|
8.8 |
HIGH
Network
|
geniusbytes
|
genius_server
|
An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges.
|
NVD-CWE-noinfo
|
CVE-2019-16653
|
2024-11-21 13:30 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223325
|
7.2 |
HIGH
Network
|
geniusbytes
|
genius_server
|
The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands.
|
NVD-CWE-noinfo
|
CVE-2019-16652
|
2024-11-21 13:30 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223326
|
7.5 |
HIGH
Network
|
mediawiki
|
abusefilter
|
An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppressed usernames and sum…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-16528
|
2024-11-21 13:30 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223327
|
6.8 |
MEDIUM
Physics
|
hom.ee
|
brain_cube_core
|
The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-16258
|
2024-11-21 13:30 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223328
|
7.5 |
HIGH
Network
|
phpbb
|
phpbb
|
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
|
CWE-94
Code Injection
|
CVE-2019-16108
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223329
|
9.8 |
CRITICAL
Network
|
netsas
|
enigma_network_management_solution
|
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of sh…
|
CWE-78
OS Command
|
CVE-2019-16072
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223330
|
8.8 |
HIGH
Network
|
netsas
|
enigma_nms
|
Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is p…
|
CWE-269
Improper Privilege Management
|
CVE-2019-16071
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|