Search Results (87742 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-12373 1 Ivanti 1 Landesk Management Suite 2024-11-21 N/A
Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.
CVE-2019-12370 1 Readdle 1 Spark 2024-11-21 6.1 Medium
The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12369 1 Typeapp 1 Typeapp 2024-11-21 6.1 Medium
The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12368 1 Edison 1 Edison Mail 2024-11-21 6.1 Medium
The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12367 1 Blixhq 1 Bluemail 2024-11-21 6.1 Medium
The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12366 1 9folders 1 Nine 2024-11-21 6.1 Medium
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12365 1 Cloudmagic 1 Newton 2024-11-21 6.1 Medium
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
CVE-2019-12362 1 Phome 1 Empirecms 2024-11-21 N/A
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
CVE-2019-12361 1 Phome 1 Empirecms 2024-11-21 N/A
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.
CVE-2019-12347 1 Netgate 1 Pfsense 2024-11-21 N/A
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
CVE-2019-12346 1 Miniorange 1 Saml Sp Single Sign On 2024-11-21 N/A
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
CVE-2019-12345 1 Kibokolabs 1 Hostel 2024-11-21 N/A
XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.
CVE-2019-12328 1 Atcom 2 A10w, A10w Firmware 2024-11-21 N/A
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.
CVE-2019-12327 1 Akuvox 2 Sp-r50p, Sp-r50p Firmware 2024-11-21 N/A
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be turned off and the credentials cannot be changed.
CVE-2019-12325 1 Htek 2 Uc902, Uc902 Firmware 2024-11-21 8.8 High
The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware version 2.0.4.4.46, which allow an attacker to crash the device (DoS) without authentication or execute code (authenticated as a user) to spawn a remote shell as a root user.
CVE-2019-12324 1 Akuvox 2 Sp-r50p, Sp-r50p Firmware 2024-11-21 N/A
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters in a POST request.
CVE-2019-12323 1 Hostingcontroller 1 Hc10 2024-11-21 N/A
The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS.
CVE-2019-12315 1 Samsung 2 Scx-824, Scx-824 Firmware 2024-11-21 N/A
Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.
CVE-2019-12313 1 Dollarshaveclub 1 Shave 2024-11-21 N/A
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
CVE-2019-12311 1 Sandline 1 Centraleyezer 2024-11-21 6.1 Medium
Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.