|
218671
|
3.3 |
LOW
Local
|
rapid7
|
metasploit
|
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable perm…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-5642
|
2024-11-21 13:45 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218672
|
9.8 |
CRITICAL
Network
|
gatech
|
computing_for_good\'s_basic_laboratory_information_system
|
Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from an instance of CWE-284, "Improper Access Control." As a result, an unauthenticat…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5617
|
2024-11-21 13:45 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218673
|
3.1 |
LOW
Network
|
nicehash
|
miner
|
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-6122
|
2024-11-21 13:45 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218674
|
3.7 |
LOW
Network
|
nicehash
|
miner
|
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, O…
|
CWE-862
Missing Authorization
|
CVE-2019-6121
|
2024-11-21 13:45 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218675
|
7.5 |
HIGH
Network
|
nicehash
|
miner
|
An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email addresses to identify …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6120
|
2024-11-21 13:45 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218676
|
4.3 |
MEDIUM
Network
|
vmware
|
sd-wan_by_velocloud
|
In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provide…
|
CWE-863
Incorrect Authorization
|
CVE-2019-5533
|
2024-11-21 13:45 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218677
|
5.9 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-5538
|
2024-11-21 13:45 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218678
|
5.9 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-5537
|
2024-11-21 13:45 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218679
|
6.5 |
MEDIUM
Network
|
vmware
|
fusion workstation esxi
|
VMware ESXi (6.7 before ESXi670-201908101-SG and 6.5 before ESXi650-201910401-SG), Workstation (15.x before 15.5.0) and Fusion (11.x before 11.5.0) contain a denial-of-service vulnerability in the sh…
|
NVD-CWE-noinfo
|
CVE-2019-5536
|
2024-11-21 13:45 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218680
|
7.5 |
HIGH
Network
|
netapp
|
clustered_data_ontap
|
Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS).
|
NVD-CWE-noinfo
|
CVE-2019-5508
|
2024-11-21 13:45 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|