|
223591
|
8.8 |
HIGH
Network
|
reddoxx
|
maildepot
|
REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
|
CWE-863
Incorrect Authorization
|
CVE-2019-19200
|
2024-11-21 13:34 |
2020-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223592
|
7.4 |
HIGH
Network
|
reddoxx
|
maildepot
|
REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-19199
|
2024-11-21 13:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223593
|
6.1 |
MEDIUM
Network
|
rittal
|
cmc_pu_iii_7030.000_firmware
|
The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19393
|
2024-11-21 13:34 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223594
|
6.5 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
|
CWE-89
SQL Injection
|
CVE-2019-19499
|
2024-11-21 13:34 |
2020-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223595
|
7.8 |
HIGH
Local
|
wowza
|
streaming_engine
|
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19455
|
2024-11-21 13:34 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223596
|
5.4 |
MEDIUM
Network
|
wowza
|
streaming_engine
|
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19453
|
2024-11-21 13:34 |
2020-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223597
|
5.9 |
MEDIUM
Network
|
silverstripe
|
silverstripe
|
Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTTP layer can be vulnerable to web cache poisoning. Through modifying the X-Origi…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-19326
|
2024-11-21 13:34 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223598
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-19338
|
2024-11-21 13:34 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223599
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affec…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-19417
|
2024-11-21 13:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223600
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affec…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-19416
|
2024-11-21 13:34 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|