|
222101
|
5.7 |
MEDIUM
Adjacent
|
redhat debian fedoraproject
|
libvirt debian_linux fedora
|
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
|
CWE-20
Improper Input Validation
|
CVE-2019-20485
|
2024-11-21 13:38 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222102
|
7.5 |
HIGH
Network
|
frappe
|
frappe
|
In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a …
|
CWE-306 CWE-552
Missing Authentication for Critical Function Files or Directories Accessible to External Parties
|
CVE-2019-20529
|
2024-11-21 13:38 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222103
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20528
|
2024-11-21 13:38 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222104
|
6.1 |
MEDIUM
Network
|
open.edx
|
ironwood
|
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20512
|
2024-11-21 13:38 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222105
|
6.1 |
MEDIUM
Network
|
frappe
|
erpnext
|
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20511
|
2024-11-21 13:38 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222106
|
9.8 |
CRITICAL
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
|
NVD-CWE-noinfo
|
CVE-2019-20498
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222107
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
|
CWE-79
Cross-site Scripting
|
CVE-2019-20497
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222108
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
|
NVD-CWE-noinfo
|
CVE-2019-20496
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222109
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
|
NVD-CWE-noinfo
|
CVE-2019-20495
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222110
|
3.3 |
LOW
Local
|
cpanel
|
cpanel
|
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-20494
|
2024-11-21 13:38 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|