|
223331
|
5.3 |
MEDIUM
Network
|
mediawiki
|
checkuser
|
An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still visible in CheckUser results in violation of MediaWiki's permissions model.
|
NVD-CWE-noinfo
|
CVE-2019-16529
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223332
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or cus…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16375
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223333
|
7.8 |
HIGH
Local
|
hancom
|
hancom_office_neo
|
The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
|
CWE-416
Use After Free
|
CVE-2019-16338
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223334
|
7.8 |
HIGH
Local
|
hancom
|
hancom_office_neo
|
The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
|
CWE-416
Use After Free
|
CVE-2019-16337
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223335
|
9.8 |
CRITICAL
Network
|
ivanti
|
workspace_control
|
An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid …
|
NVD-CWE-noinfo
|
CVE-2019-16382
|
2024-11-21 13:30 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223336
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
|
CWE-200 CWE-532
Information Exposure Inclusion of Sensitive Information in Log Files
|
CVE-2019-16157
|
2024-11-21 13:30 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223337
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross S…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16156
|
2024-11-21 13:30 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223338
|
4.3 |
MEDIUM
Network
|
phpbb
|
phpbb
|
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
|
CWE-352
Origin Validation Error
|
CVE-2019-16107
|
2024-11-21 13:30 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223339
|
7.5 |
HIGH
Network
|
linuxfoundation
|
open_network_operating_system
|
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-16302
|
2024-11-21 13:30 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223340
|
7.5 |
HIGH
Network
|
linuxfoundation
|
open_network_operating_system
|
An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event listener does not handle the following event type…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-16301
|
2024-11-21 13:30 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|