|
220991
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5613
|
2024-11-21 13:45 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220992
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.
|
CWE-863
Incorrect Authorization
|
CVE-2019-5474
|
2024-11-21 13:45 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220993
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.
|
NVD-CWE-Other CWE-269
Improper Privilege Management
|
CVE-2019-5472
|
2024-11-21 13:45 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220994
|
6.1 |
MEDIUM
Network
|
f-revocrm
|
f-revocrm
|
Cross-site scripting vulnerability in F-RevoCRM 6.0 to F-RevoCRM 6.5 patch6 (version 6 series) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6036
|
2024-11-21 13:45 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220995
|
5.5 |
MEDIUM
Local
|
fortinet
|
fortios
|
Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of system's builtin local certificates via unsetting the k…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-5593
|
2024-11-21 13:45 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220996
|
7.1 |
HIGH
Local
|
rapid7
|
appspider
|
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijack…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-5647
|
2024-11-21 13:45 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220997
|
7.5 |
HIGH
Network
|
anglers-net
|
cgi_an-anlyzer
|
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-5990
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220998
|
6.1 |
MEDIUM
Network
|
anglers-net
|
cgi_an-anlyzer
|
DOM-based cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Analysis Ob…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5989
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220999
|
6.1 |
MEDIUM
Network
|
anglers-net
|
cgi_an-anlyzer
|
Stored cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Management Pag…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5988
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221000
|
8.8 |
HIGH
Network
|
anglers-net
|
cgi_an-anlyzer
|
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.
|
CWE-78
OS Command
|
CVE-2019-5987
|
2024-11-21 13:45 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|