|
224541
|
5.4 |
MEDIUM
Network
|
swisscom
|
centro_grande_firmware
|
Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19941
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224542
|
7.2 |
HIGH
Network
|
swisscom
|
centro_grande_firmware
|
Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injectio…
|
CWE-78
OS Command
|
CVE-2019-19940
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224543
|
4.8 |
MEDIUM
Network
|
sangoma
|
freepbx
|
An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Sup…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19851
|
2024-11-21 13:35 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224544
|
7.5 |
HIGH
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to access the list of connected users as well as the session cookie for each user. …
|
NVD-CWE-noinfo
|
CVE-2019-19611
|
2024-11-21 13:35 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224545
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-19799
|
2024-11-21 13:35 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224546
|
6.0 |
MEDIUM
Local
|
lenovo
|
xclarity_administrator
|
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear t…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-19756
|
2024-11-21 13:35 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224547
|
7.5 |
HIGH
Network
|
halvotec
|
raquest
|
An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed…
|
CWE-74
Injection
|
CVE-2019-19614
|
2024-11-21 13:35 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224548
|
5.4 |
MEDIUM
Network
|
lexmark
|
cs31x_firmware cs41x_firmware cs51x_firmware cx310_firmware cx410_firmware xc2130_firmware cx510_firmware xc2132_firmware ms310_firmware ms312_firmware ms317_firmware
|
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19773
|
2024-11-21 13:35 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224549
|
5.4 |
MEDIUM
Network
|
lexmark
|
cs31x_firmware cs41x_firmware cs51x_firmware cx310_firmware cx410_firmware xc2130_firmware cx510_firmware xc2132_firmware ms310_firmware ms312_firmware ms317_firmware
|
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19772
|
2024-11-21 13:35 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224550
|
6.7 |
MEDIUM
Local
|
eset
|
cyber_security
|
A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned files.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19792
|
2024-11-21 13:35 |
2020-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|