|
224461
|
3.7 |
LOW
Network
|
cisco
|
webex_business_suite_39
|
Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-1866
|
2024-11-21 13:37 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224462
|
7.8 |
HIGH
Local
|
zsh fedoraproject debian apple
|
zsh fedora debian_linux mac_os_x iphone_os watchos tvos ipados
|
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by …
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2019-20044
|
2024-11-21 13:37 |
2020-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224463
|
8.4 |
HIGH
Local
|
cisco
|
ios_xe
|
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default …
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-1950
|
2024-11-21 13:37 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224464
|
9.8 |
CRITICAL
Network
|
s3india
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may al…
|
CWE-287
Improper Authentication
|
CVE-2019-20046
|
2024-11-21 13:37 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224465
|
7.5 |
HIGH
Network
|
s3india
|
husky_rtu_6049-e70_firmware
|
The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active aut…
|
CWE-20
Improper Input Validation
|
CVE-2019-20045
|
2024-11-21 13:37 |
2020-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224466
|
9.8 |
CRITICAL
Network
|
mfscripts
|
yetishare
|
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
|
CWE-287
Improper Authentication
|
CVE-2019-20062
|
2024-11-21 13:37 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224467
|
7.5 |
HIGH
Network
|
mfscripts
|
yetishare
|
The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose th…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-20061
|
2024-11-21 13:37 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224468
|
7.5 |
HIGH
Network
|
mfscripts
|
yetishare
|
MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensiti…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2019-20060
|
2024-11-21 13:37 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224469
|
8.8 |
HIGH
Network
|
mfscripts
|
yetishare
|
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inj…
|
CWE-352 CWE-89
Origin Validation Error SQL Injection
|
CVE-2019-20059
|
2024-11-21 13:37 |
2020-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224470
|
6.8 |
MEDIUM
Network
|
artica
|
pandora_fms
|
Pandora FMS = 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The expl…
|
CWE-78
OS Command
|
CVE-2019-20050
|
2024-11-21 13:37 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|