Total
8186 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-15085 | 1 Prise | 1 Adas | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. | |||||
CVE-2019-15045 | 1 Zohocorp | 1 Manageengine Servicedesk Plus | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality | |||||
CVE-2019-14839 | 1 Redhat | 3 Business-central, Descision Manager, Process Automation | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. | |||||
CVE-2019-14800 | 1 Foliovision | 1 Fv Flowplayer Video Player | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI. | |||||
CVE-2019-14666 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes. | |||||
CVE-2019-14480 | 1 Adremsoft | 1 Netcrunch | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges. | |||||
CVE-2019-14367 | 1 Slack-chat Project | 1 Slack-chat | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). | |||||
CVE-2019-14366 | 1 Slack | 1 Wp Slacksync | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). | |||||
CVE-2019-14365 | 1 Intercom | 1 Intercom | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.). | |||||
CVE-2019-14301 | 1 Ricoh | 104 M 2700, M 2700 Firmware, M 2701 and 101 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2). | |||||
CVE-2019-14280 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | |||||
CVE-2019-13744 | 4 Debian, Fedoraproject, Google and 1 more | 7 Debian Linux, Fedora, Chrome and 4 more | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |||||
CVE-2019-13737 | 4 Debian, Fedoraproject, Google and 1 more | 7 Debian Linux, Fedora, Chrome and 4 more | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | |||||
CVE-2019-13557 | 1 Philips | 2 Tasy Emr, Tasy Webportal | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information. | |||||
CVE-2019-13457 | 1 Otrs | 1 Otrs | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAccess setting is turned on. | |||||
CVE-2019-13421 | 1 Search-guard | 1 Search Guard | 2024-11-21 | 4.0 MEDIUM | 4.9 MEDIUM |
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database. | |||||
CVE-2019-13419 | 1 Search-guard | 1 Search Guard | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked. | |||||
CVE-2019-13417 | 1 Search-guard | 1 Search Guard | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated. | |||||
CVE-2019-13410 | 1 Topmeeting | 1 Topmeeting | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page. | |||||
CVE-2019-13314 | 1 Redhat | 1 Virt-bootstrap | 2024-11-21 | 2.1 LOW | 7.8 HIGH |
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. |