Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (88023 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2019-19487 | 1 Centreon | 1 Centreon | 2024-11-21 | 8.8 High |
| Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test. | ||||
| CVE-2019-19469 | 1 Zmanda | 1 Amanda | 2024-11-21 | 8.8 High |
| In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials. | ||||
| CVE-2019-19466 | 1 Sceditor | 1 Sceditor | 2024-11-21 | 6.1 Medium |
| SCEditor 2.1.3 allows XSS. | ||||
| CVE-2019-19461 | 1 Teampasswordmanager | 1 Team Password Manager | 2024-11-21 | 5.4 Medium |
| Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title. | ||||
| CVE-2019-19457 | 1 Saltosystem | 1 Proaccess Space | 2024-11-21 | 5.4 Medium |
| SALTO ProAccess SPACE 5.4.3.0 allows XSS. | ||||
| CVE-2019-19456 | 1 Wowza | 1 Streaming Engine | 2024-11-21 | 6.1 Medium |
| A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0. | ||||
| CVE-2019-19455 | 1 Wowza | 1 Streaming Engine | 2024-11-21 | 7.8 High |
| Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5. | ||||
| CVE-2019-19453 | 1 Wowza | 1 Streaming Engine | 2024-11-21 | 5.4 Medium |
| Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5. | ||||
| CVE-2019-19452 | 1 Patriotmemory | 1 Viper Rgb Driver | 2024-11-21 | 7.8 High |
| A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges. | ||||
| CVE-2019-19394 | 1 Northern.tech | 1 Cfengine | 2024-11-21 | 6.1 Medium |
| Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0. | ||||
| CVE-2019-19393 | 1 Rittal | 2 Cmc Pu Iii 7030.000, Cmc Pu Iii 7030.000 Firmware | 2024-11-21 | 6.1 Medium |
| The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session. | ||||
| CVE-2019-19390 | 1 Matrix42 | 1 Workspace Management | 2024-11-21 | 5.4 Medium |
| The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues. | ||||
| CVE-2019-19389 | 1 Jetbrains | 1 Ktor | 2024-11-21 | 5.4 Medium |
| JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. | ||||
| CVE-2019-19388 | 1 Fusionpbx | 1 Fusionpbx | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter. | ||||
| CVE-2019-19387 | 1 Fusionpbx | 1 Fusionpbx | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter. | ||||
| CVE-2019-19386 | 1 Fusionpbx | 1 Fusionpbx | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter. | ||||
| CVE-2019-19385 | 1 Fusionpbx | 1 Fusionpbx | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter. | ||||
| CVE-2019-19384 | 1 Fusionpbx | 1 Fusionpbx | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter. | ||||
| CVE-2019-19382 | 1 Maxpcsecure | 1 Anti Virus Plus | 2024-11-21 | 7.8 High |
| Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation. | ||||
| CVE-2019-19381 | 1 Abacus | 1 Abacus | 2024-11-21 | 6.1 Medium |
| oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_0000 before prior to R4 (20.11.2019 Hotfix) allows Reflected Cross Site Scripting (XSS) via an error message. | ||||