CVE-2019-15000 to CVE-2019-15999
175 CVEs with public proof-of-concept exploits.
- CVE-2019-150292 PoCsFusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file…
- CVE-2019-150301 PoCIn the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a…
- CVE-2019-150311 PoCIn the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an…
- CVE-2019-150331 PoCPydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file…
- CVE-2019-150391 PoCAn issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
- CVE-2019-150432 PoCsIn Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of…
- CVE-2019-150452 PoCsAjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended…
- CVE-2019-150463 PoCsZoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS)…
- CVE-2019-150471 PoCAn issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at…
- CVE-2019-150481 PoCAn issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
- CVE-2019-150491 PoCAn issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
- CVE-2019-150501 PoCAn issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
- CVE-2019-150511 PoCAn issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection…
- CVE-2019-150531 PoCThe "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection…
- CVE-2019-150551 PoCMikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete…
- CVE-2019-150581 PoCstb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or…
- CVE-2019-150622 PoCsAn issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his…
- CVE-2019-150812 PoCsOpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the…
- CVE-2019-150831 PoCDefault installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local…
- CVE-2019-150841 PoCRealtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker…
- CVE-2019-150871 PoCAn issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading…
- CVE-2019-150922 PoCsThe webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url,…
- CVE-2019-150951 PoCDWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
- CVE-2019-151021 PoCAn issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any…
- CVE-2019-151042 PoCsAn issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in…
- CVE-2019-151052 PoCsAn issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in…
- CVE-2019-151062 PoCsAn issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute…
- CVE-2019-1510754 PoCsKEVAn issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
- CVE-2019-151201 PoCThe Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
- CVE-2019-151266 PoCsAn issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to…
- CVE-2019-151281 PoCiF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
- CVE-2019-151291 PoCThe Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files…
- CVE-2019-151301 PoCThe Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a…
- CVE-2019-151341 PoCRIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for…
- CVE-2019-151401 PoCcoders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and application crash) or…
- CVE-2019-151421 PoCIn DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in…
- CVE-2019-151461 PoCGoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c.
- CVE-2019-151471 PoCGoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c.
- CVE-2019-151481 PoCGoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c.
- CVE-2019-151661 PoClmp_print in tcpdump lacks certain boundary checks
- CVE-2019-152241 PoCThe rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third…
- CVE-2019-152281 PoCFUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions.…
- CVE-2019-152291 PoCFUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the…
- CVE-2019-152331 PoCThe Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator…
- CVE-2019-152351 PoCCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from…
- CVE-2019-152381 PoCThe cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
- CVE-2019-152391 PoCIn the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to…
- CVE-2019-152532 PoCsCisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
- CVE-2019-152581 PoCCisco SPA100 Series Analog Telephone Adapters Web Management Interface Denial of Service Vulnerability
- CVE-2019-152762 PoCsCisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
- CVE-2019-153141 PoCtiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a…
- CVE-2019-153162 PoCsValve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM)…
- CVE-2019-153241 PoCThe ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
- CVE-2019-154781 PoCStatus Board 1.1.81 has reflected XSS via logic.ts.
- CVE-2019-154791 PoCStatus Board 1.1.81 has reflected XSS via dashboard.ts.
- CVE-2019-154821 PoCselectize-plugin-a11y before 1.1.0 has XSS via the msg field.
- CVE-2019-154991 PoCCodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction…
- CVE-2019-155013 PoCsReflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
- CVE-2019-155022 PoCsThe TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka…
- CVE-2019-155101 PoCManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the…
- CVE-2019-155111 PoCAn exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access…
- CVE-2019-155143 PoCsThe Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is…
- CVE-2019-155321 PoCCyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
- CVE-2019-155751 PoCA command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API…
- CVE-2019-155761 PoCAn information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private…
- CVE-2019-155771 PoCAn information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be…
- CVE-2019-155801 PoCAn information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request…
- CVE-2019-155841 PoCA denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown…
- CVE-2019-155884 PoCsThere is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code…
- CVE-2019-155891 PoCAn improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to…
- CVE-2019-155911 PoCAn improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning…
- CVE-2019-155931 PoCGitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service…
- CVE-2019-155961 PoCA path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within…
- CVE-2019-155981 PoCA Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the…
- CVE-2019-156021 PoCThe fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability…
- CVE-2019-156031 PoCThe seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a…
- CVE-2019-156041 PoCImproper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
- CVE-2019-156052 PoCsHTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
- CVE-2019-156061 PoCIncluding trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value…
- CVE-2019-156071 PoCA stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of…
- CVE-2019-156081 PoCThe package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to…
- CVE-2019-156091 PoCThe kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
- CVE-2019-156221 PoCNot strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables…
- CVE-2019-156231 PoCExposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup…
- CVE-2019-156241 PoCImproper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
- CVE-2019-156271 PoCVersions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to…
- CVE-2019-156372 PoCsNumerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or…
- CVE-2019-156422 PoCsrpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an…
- CVE-2019-156471 PoCThe groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
- CVE-2019-156481 PoCThe insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or…
- CVE-2019-156521 PoCThe web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for error messages,…
- CVE-2019-156531 PoCComba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source…
- CVE-2019-156541 PoCComba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to…
- CVE-2019-156551 PoCD-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management…
- CVE-2019-156561 PoCD-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on…
- CVE-2019-156571 PoCIn eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
- CVE-2019-156581 PoCconnect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
- CVE-2019-157011 PoCcomponents/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process…
- CVE-2019-157021 PoCIn the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a…
- CVE-2019-157071 PoCAn improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to…
- CVE-2019-157131 PoCThe my-calendar plugin before 3.1.10 for WordPress has XSS.
- CVE-2019-157153 PoCsMantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
- CVE-2019-157191 PoCAltair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails…
- CVE-2019-157413 PoCsAn issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
- CVE-2019-157423 PoCsA local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application. A local attacker…
- CVE-2019-157451 PoCThe Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and…
- CVE-2019-157523 PoCsKEVDocker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse…
- CVE-2019-157581 PoCAn issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at…
- CVE-2019-157591 PoCAn issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in…
- CVE-2019-157661 PoCThe KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the…
- CVE-2019-157711 PoCThe nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-157721 PoCThe nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-157731 PoCThe nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-157742 PoCsThe nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-157751 PoCThe nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-157761 PoCThe simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a…
- CVE-2019-157771 PoCThe shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
- CVE-2019-157821 PoCWebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
- CVE-2019-157891 PoCMicrok8s Privilege Escalation Vulnerability
- CVE-2019-157901 PoCApport reads PID files with elevated privileges
- CVE-2019-157911 PoCReference count underflow in shiftfs
- CVE-2019-157921 PoCType confusion in shiftfs
- CVE-2019-157931 PoCMishandling of file-system uid/gid with namespaces in shiftfs
- CVE-2019-157941 PoCReference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
- CVE-2019-158091 PoCSmart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in…
- CVE-2019-158113 PoCsIn DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
- CVE-2019-158134 PoCsMultiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a…
- CVE-2019-158141 PoCMultiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
- CVE-2019-158231 PoCThe wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
- CVE-2019-158271 PoCThe onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
- CVE-2019-158281 PoCThe one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
- CVE-2019-158291 PoCThe photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
- CVE-2019-158321 PoCThe visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
- CVE-2019-158371 PoCThe webp-express plugin before 0.14.8 for WordPress has stored XSS.
- CVE-2019-158462 PoCsExim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.
- CVE-2019-158491 PoCeQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the victim. After the…
- CVE-2019-158501 PoCeQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated attacker can…
- CVE-2019-158584 PoCsadmin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options…
- CVE-2019-158591 PoCPassword disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a…
- CVE-2019-158601 PoCXpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
- CVE-2019-158671 PoCThe slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber…
- CVE-2019-158691 PoCThe JobCareer theme before 2.5.1 for WordPress has stored XSS.
- CVE-2019-158701 PoCThe CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
- CVE-2019-158731 PoCThe profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an…
- CVE-2019-158895 PoCsThe download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or…
- CVE-2019-158961 PoCAn issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the…
- CVE-2019-159101 PoCAn issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the…
- CVE-2019-159111 PoCAn issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key…
- CVE-2019-159121 PoCAn issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the…
- CVE-2019-159131 PoCAn issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in…
- CVE-2019-159141 PoCAn issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center…
- CVE-2019-159151 PoCAn issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network…
- CVE-2019-159301 PoCIntesync Solismed 3.3sp allows Clickjacking.
- CVE-2019-159311 PoCIntesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
- CVE-2019-159321 PoCIntesync Solismed 3.3sp has Incorrect Access Control.
- CVE-2019-159331 PoCIntesync Solismed 3.3sp has SQL Injection.
- CVE-2019-159341 PoCIntesync Solismed 3.3sp has CSRF.
- CVE-2019-159351 PoCIntesync Solismed 3.3sp has XSS.
- CVE-2019-159361 PoCIntesync Solismed 3.3sp allows Insecure File Upload.
- CVE-2019-159401 PoCVicture PC530 devices allow unauthenticated TELNET access as root.
- CVE-2019-159421 PoCFFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in…
- CVE-2019-159432 PoCsvphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by…
- CVE-2019-159497 PoCsKEVNagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as…
- CVE-2019-159501 PoCThe CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
- CVE-2019-159543 PoCsAn issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution…
- CVE-2019-159551 PoCAn issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random…
- CVE-2019-159611 PoCClam AntiVirus (ClamAV) Software Email Parsing Vulnerability
- CVE-2019-159721 PoCCisco Unified Communications Manager SQL Injection Vulnerability
- CVE-2019-159753 PoCsCisco Data Center Network Manager Authentication Bypass Vulnerabilities
- CVE-2019-159762 PoCsCisco Data Center Network Manager Authentication Bypass Vulnerabilities
- CVE-2019-159772 PoCsCisco Data Center Network Manager Authentication Bypass Vulnerabilities
- CVE-2019-159782 PoCsCisco Data Center Network Manager Command Injection Vulnerabilities
- CVE-2019-159842 PoCsCisco Data Center Network Manager SQL Injection Vulnerabilities
- CVE-2019-159932 PoCsCisco Small Business Switches Information Disclosure Vulnerability
- CVE-2019-159991 PoCCisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability