CVE-2019-10000 to CVE-2019-10999
177 CVEs with public proof-of-concept exploits.
- CVE-2019-100082 PoCsZoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically…
- CVE-2019-100092 PoCsA Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to…
- CVE-2019-100181 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.
- CVE-2019-100191 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes.
- CVE-2019-100201 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.
- CVE-2019-100211 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.
- CVE-2019-100221 PoCAn issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.
- CVE-2019-100231 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.
- CVE-2019-100241 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.
- CVE-2019-100251 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
- CVE-2019-100261 PoCAn issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.
- CVE-2019-100272 PoCsPHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
- CVE-2019-100381 PoCEvernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the…
- CVE-2019-100391 PoCThe D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from…
- CVE-2019-100401 PoCThe D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from…
- CVE-2019-100411 PoCThe D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from…
- CVE-2019-100421 PoCThe D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from…
- CVE-2019-100611 PoCutils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not…
- CVE-2019-100621 PoCThe HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The…
- CVE-2019-100641 PoChostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or…
- CVE-2019-100685 PoCsKEVAn issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure…
- CVE-2019-100761 PoCA carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to…
- CVE-2019-100771 PoCA carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session…
- CVE-2019-100781 PoCA carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to…
- CVE-2019-100891 PoCOn Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache…
- CVE-2019-100901 PoCOn Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache…
- CVE-2019-100925 PoCsIn Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker…
- CVE-2019-100982 PoCsIn Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by…
- CVE-2019-101011 PoCJetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing…
- CVE-2019-101092 PoCsAn Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before…
- CVE-2019-101232 PoCsSQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an…
- CVE-2019-101432 PoCsIt was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who…
- CVE-2019-1014929 PoCsKEVA flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in…
- CVE-2019-101721 PoCA flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720…
- CVE-2019-101811 PoCIt was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising…
- CVE-2019-101821 PoCIt was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could…
- CVE-2019-101851 PoCIt was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR…
- CVE-2019-102071 PoCA flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An…
- CVE-2019-102191 PoCA vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of…
- CVE-2019-102201 PoCLinux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
- CVE-2019-102261 PoCHTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.…
- CVE-2019-102271 PoCopenITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
- CVE-2019-102321 PoCTeclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
- CVE-2019-102391 PoCRobotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user…
- CVE-2019-102491 PoCAll Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been…
- CVE-2019-102501 PoCUCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks.
- CVE-2019-102511 PoCThe UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft…
- CVE-2019-102531 PoCA Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data…
- CVE-2019-102612 PoCsCentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS…
- CVE-2019-102661 PoCAn issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible…
- CVE-2019-102675 PoCsAn insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into…
- CVE-2019-102691 PoCBWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long…
- CVE-2019-102732 PoCsInformation leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to…
- CVE-2019-102762 PoCsWestern Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file…
- CVE-2019-103221 PoCA missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed…
- CVE-2019-103492 PoCsA stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure…
- CVE-2019-103521 PoCA path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in…
- CVE-2019-103924 PoCsJenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git…
- CVE-2019-104051 PoCJenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing…
- CVE-2019-104754 PoCsA reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript…
- CVE-2019-105291 PoCPossible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set_page_dirty() in…
- CVE-2019-105671 PoCThere is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existing commands could…
- CVE-2019-106301 PoCA plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the…
- CVE-2019-106311 PoCShell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute…
- CVE-2019-106321 PoCA directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a lower privileged…
- CVE-2019-106331 PoCAn eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a remote authenticated…
- CVE-2019-106341 PoCAn XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitrary JavaScript or…
- CVE-2019-106441 PoCAn issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.
- CVE-2019-106472 PoCsZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the…
- CVE-2019-106491 PoCIn ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a…
- CVE-2019-106501 PoCIn ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an…
- CVE-2019-106521 PoCAn issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related…
- CVE-2019-106541 PoCThe lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a…
- CVE-2019-106553 PoCsGrandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices…
- CVE-2019-106641 PoCDomoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
- CVE-2019-106693 PoCsAn issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in…
- CVE-2019-106731 PoCA CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to…
- CVE-2019-106774 PoCsMultiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote…
- CVE-2019-106783 PoCsDomoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
- CVE-2019-106792 PoCsThomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson…
- CVE-2019-106841 PoCApplication/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the…
- CVE-2019-106852 PoCsA Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
- CVE-2019-106871 PoCKBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id…
- CVE-2019-106923 PoCsIn the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names…
- CVE-2019-107081 PoCS-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
- CVE-2019-107093 PoCsAsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a…
- CVE-2019-107162 PoCsAn Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated security…
- CVE-2019-107172 PoCsBlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
- CVE-2019-107181 PoCBlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and…
- CVE-2019-107192 PoCsBlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to…
- CVE-2019-107202 PoCsBlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE:…
- CVE-2019-107231 PoCAn issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory…
- CVE-2019-107321 PoCIn KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart…
- CVE-2019-107341 PoCIn KDE Trojita 0.7, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart…
- CVE-2019-107351 PoCIn Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart…
- CVE-2019-107423 PoCsAxios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content…
- CVE-2019-107431 PoCAll versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially…
- CVE-2019-107443 PoCsVersions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or…
- CVE-2019-107452 PoCsassign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked…
- CVE-2019-107462 PoCsmixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into…
- CVE-2019-107472 PoCsset-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or…
- CVE-2019-107481 PoCSequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly…
- CVE-2019-107491 PoCsequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly sanitized in the…
- CVE-2019-107502 PoCsdeeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying…
- CVE-2019-107511 PoCAll versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary…
- CVE-2019-107545 PoCsMultiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for token and ID…
- CVE-2019-107561 PoCIt is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting…
- CVE-2019-107571 PoCknex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect,…
- CVE-2019-1075810 PoCsKEVmongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm`…
- CVE-2019-107591 PoCsafer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and…
- CVE-2019-107601 PoCsafer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and…
- CVE-2019-107612 PoCsSandbox Bypass
- CVE-2019-107641 PoCIn elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private…
- CVE-2019-107651 PoCiobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
- CVE-2019-107661 PoCPixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
- CVE-2019-107671 PoCAn attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like…
- CVE-2019-107681 PoCIn AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a…
- CVE-2019-107691 PoCsafer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are…
- CVE-2019-107701 PoCAll versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects…
- CVE-2019-107711 PoCCharacters in the GET url path are not properly escaped and can be reflected in the server response.
- CVE-2019-107721 PoCIt is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace…
- CVE-2019-107731 PoCIn Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using…
- CVE-2019-107751 PoCecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.
- CVE-2019-107761 PoCIn "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects…
- CVE-2019-107771 PoCIn aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function…
- CVE-2019-107781 PoCdevcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The…
- CVE-2019-107792 PoCsAll versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting.…
- CVE-2019-107801 PoCBibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby…
- CVE-2019-107811 PoCIn schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used…
- CVE-2019-107831 PoCAll versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the…
- CVE-2019-107841 PoCphppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application.…
- CVE-2019-107851 PoCdojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due…
- CVE-2019-107861 PoCnetwork-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
- CVE-2019-107871 PoCim-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within…
- CVE-2019-107881 PoCim-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject…
- CVE-2019-107891 PoCAll versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users…
- CVE-2019-107901 PoCtaffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into…
- CVE-2019-107911 PoCpromise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can…
- CVE-2019-107921 PoCbodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of…
- CVE-2019-107931 PoCdot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of…
- CVE-2019-107951 PoCundefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying properties of…
- CVE-2019-107991 PoCcompile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is…
- CVE-2019-108001 PoCCommand Injection
- CVE-2019-108011 PoCenpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any…
- CVE-2019-108031 PoCpush-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated…
- CVE-2019-108041 PoCserial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the…
- CVE-2019-108051 PoCvalib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions…
- CVE-2019-108061 PoCvega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into…
- CVE-2019-108071 PoCBlamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the…
- CVE-2019-108081 PoCutilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties…
- CVE-2019-108421 PoCArbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An…
- CVE-2019-108461 PoCComputrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and password reset page via…
- CVE-2019-108471 PoCComputrols CBAS 18.0.0 allows Cross-Site Request Forgery.
- CVE-2019-108481 PoCComputrols CBAS 18.0.0 allows Username Enumeration.
- CVE-2019-108491 PoCComputrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
- CVE-2019-108561 PoCIn Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for…
- CVE-2019-108632 PoCsA command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new…
- CVE-2019-108662 PoCsIn the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the…
- CVE-2019-108675 PoCsAn issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit,…
- CVE-2019-108691 PoCPath Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is…
- CVE-2019-108711 PoCAn issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at…
- CVE-2019-108721 PoCAn issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at…
- CVE-2019-108731 PoCAn issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at…
- CVE-2019-108741 PoCCross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary…
- CVE-2019-108752 PoCsA URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native browser) and Mint…
- CVE-2019-108872 PoCsA reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82.130611 allows…
- CVE-2019-108931 PoCCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent…
- CVE-2019-108981 PoCIn Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by…
- CVE-2019-109001 PoCIn Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown…
- CVE-2019-109031 PoCIn Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in…
- CVE-2019-109151 PoCA vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration web application (TIA…
- CVE-2019-109193 PoCsA vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp…
- CVE-2019-109213 PoCsA vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the…
- CVE-2019-109454 PoCsAn issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing…
- CVE-2019-109632 PoCsMoxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which…
- CVE-2019-109691 PoCMoxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on…
- CVE-2019-109993 PoCsThe D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a…