|
224561
|
6.5 |
MEDIUM
Network
|
seling
|
visual_access_manager
|
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse fu…
|
CWE-352
Origin Validation Error
|
CVE-2019-19987
|
2024-11-21 13:35 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224562
|
7.5 |
HIGH
Network
|
seling
|
visual_access_manager
|
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication is able to execute arbitrary SQL SELECT statements by injecting the HTTP (POST o…
|
CWE-89
SQL Injection
|
CVE-2019-19986
|
2024-11-21 13:35 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224563
|
7.5 |
HIGH
Network
|
atos
|
unify_openscape_uc_web_client
|
Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to ge…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-19866
|
2024-11-21 13:35 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224564
|
6.1 |
MEDIUM
Network
|
atos
|
unify_openscape_uc_web_client
|
Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary J…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19865
|
2024-11-21 13:35 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224565
|
4.7 |
MEDIUM
Local
|
trendmicro
|
antivirus_\+_security_2019 internet_security_2019 maximum_security_2019 officescan_cloud premium_security_2019
|
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain…
|
NVD-CWE-noinfo
|
CVE-2019-19694
|
2024-11-21 13:35 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224566
|
7.8 |
HIGH
Local
|
ea
|
origin
|
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.ex…
|
NVD-CWE-Other
|
CVE-2019-19741
|
2024-11-21 13:35 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224567
|
7.5 |
HIGH
Network
|
hashicorp
|
sentinel
|
HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.
|
NVD-CWE-noinfo
|
CVE-2019-19879
|
2024-11-21 13:35 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224568
|
6.1 |
MEDIUM
Network
|
lenovo
|
ez_media_\&_backup_center_ix2_firmware ez_media_\&_backup_center_ix2-dl_firmware
|
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untruste…
|
CWE-601
Open Redirect
|
CVE-2019-19758
|
2024-11-21 13:35 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224569
|
5.4 |
MEDIUM
Network
|
lenovo
|
xclarity_administrator
|
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19757
|
2024-11-21 13:35 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224570
|
7.0 |
HIGH
Local
|
linuxfoundation debian opensuse canonical redhat
|
runc debian_linux leap ubuntu_linux openshift_container_platform
|
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers wit…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-19921
|
2024-11-21 13:35 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|