|
222711
|
4.3 |
MEDIUM
Network
|
arxes-tolina
|
arxes-tolina
|
arxes-tolina 3.0.0 allows User Enumeration.
|
CWE-200
Information Exposure
|
CVE-2019-19677
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222712
|
9.6 |
CRITICAL
Network
|
arxes-tolina
|
arxes-tolina
|
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlz…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-19676
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222713
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date field…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19852
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222714
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19615
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222715
|
5.2 |
MEDIUM
Adjacent
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site…
|
CWE-601
Open Redirect
|
CVE-2019-19613
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222716
|
5.4 |
MEDIUM
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19612
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222717
|
5.4 |
MEDIUM
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
|
CWE-384
Session Fixation
|
CVE-2019-19610
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222718
|
7.2 |
HIGH
Network
|
jfrog
|
artifactory
|
In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."
|
CWE-862
Missing Authorization
|
CVE-2019-19937
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222719
|
6.5 |
MEDIUM
Network
|
dradisframework
|
dradis
|
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-19946
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222720
|
7.5 |
HIGH
Network
|
openwrt
|
openwrt
|
uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an…
|
CWE-125 CWE-681
Out-of-bounds Read Incorrect Conversion between Numeric Types
|
CVE-2019-19945
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|