|
223361
|
9.8 |
CRITICAL
Network
|
tellabs
|
optical_line_terminal_1150_firmware
|
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2…
|
CWE-78
OS Command
|
CVE-2019-19148
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223362
|
7.8 |
HIGH
Local
|
redhat
|
openshift
|
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/media…
|
-
|
CVE-2019-19345
|
2024-11-21 13:34 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223363
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
|
CWE-78
OS Command
|
CVE-2019-19487
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223364
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon
|
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.
|
CWE-22
Path Traversal
|
CVE-2019-19486
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223365
|
6.1 |
MEDIUM
Network
|
centreon
|
centreon
|
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
|
CWE-601
Open Redirect
|
CVE-2019-19484
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223366
|
7.2 |
HIGH
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.
|
CWE-89
SQL Injection
|
CVE-2019-19029
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223367
|
4.9 |
MEDIUM
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.
|
CWE-89
SQL Injection
|
CVE-2019-19026
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223368
|
8.8 |
HIGH
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
|
CWE-352
Origin Validation Error
|
CVE-2019-19025
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223369
|
8.8 |
HIGH
Network
|
linuxfoundation pivotal
|
harbor vmware_harbor_registry
|
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.
|
NVD-CWE-noinfo
|
CVE-2019-19023
|
2024-11-21 13:34 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223370
|
6.1 |
MEDIUM
Network
|
ovirt redhat
|
ovirt-engine virtualization
|
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This fla…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19336
|
2024-11-21 13:34 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|