|
218991
|
7.6 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2019-5991
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218992
|
8.8 |
HIGH
Network
|
ntt-east ntt-west
|
pr-s300ne_firmware rt-s300ne_firmware rv-s340ne_firmware pr-s300hi_firmware rt-s300hi_firmware rv-s340hi_firmware pr-s300se_firmware rt-s300se_firmware rv-s340se_firmware p…
|
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/R…
|
CWE-352
Origin Validation Error
|
CVE-2019-5986
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218993
|
6.1 |
MEDIUM
Network
|
ntt-east ntt-west
|
pr-s300ne_firmware rt-s300ne_firmware rv-s340ne_firmware pr-s300hi_firmware rt-s300hi_firmware rv-s340hi_firmware pr-s300se_firmware rt-s300se_firmware rv-s340se_firmware p…
|
Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firm…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5985
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218994
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
|
CWE-601
Open Redirect
|
CVE-2019-5978
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218995
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
|
CWE-74
Injection
|
CVE-2019-5977
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218996
|
4.9 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2019-5976
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218997
|
5.4 |
MEDIUM
Network
|
cybozu
|
garoon
|
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5975
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218998
|
6.5 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2019-5956
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218999
|
5.3 |
MEDIUM
Network
|
netapp
|
oncommand_workflow_automation
|
OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-5503
|
2024-11-21 13:45 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219000
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4.
|
CWE-287
Improper Authentication
|
CVE-2019-5473
|
2024-11-21 13:45 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|