Vulnerabilities (CVE)

Filtered by CWE-200
Total 8186 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15085 1 Prise 1 Adas 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
CVE-2019-15045 1 Zohocorp 1 Manageengine Servicedesk Plus 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
CVE-2019-14839 1 Redhat 3 Business-central, Descision Manager, Process Automation 2024-11-21 5.0 MEDIUM 7.5 HIGH
It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.
CVE-2019-14800 1 Foliovision 1 Fv Flowplayer Video Player 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI.
CVE-2019-14666 1 Glpi-project 1 Glpi 2024-11-21 6.5 MEDIUM 8.8 HIGH
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability can be exploited to take control of admin account. This vulnerability could be also abused to obtain other sensitive fields like API keys or password hashes.
CVE-2019-14480 1 Adremsoft 1 Netcrunch 2024-11-21 7.5 HIGH 9.8 CRITICAL
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
CVE-2019-14367 1 Slack-chat Project 1 Slack-chat 2024-11-21 5.0 MEDIUM 7.5 HIGH
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14366 1 Slack 1 Wp Slacksync 2024-11-21 5.0 MEDIUM 7.5 HIGH
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14365 1 Intercom 1 Intercom 2024-11-21 5.0 MEDIUM 7.5 HIGH
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
CVE-2019-14301 1 Ricoh 104 M 2700, M 2700 Firmware, M 2701 and 101 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
CVE-2019-14280 1 Craftcms 1 Craft Cms 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
CVE-2019-13744 4 Debian, Fedoraproject, Google and 1 more 7 Debian Linux, Fedora, Chrome and 4 more 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2019-13737 4 Debian, Fedoraproject, Google and 1 more 7 Debian Linux, Fedora, Chrome and 4 more 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-13557 1 Philips 2 Tasy Emr, Tasy Webportal 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.
CVE-2019-13457 1 Otrs 1 Otrs 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8. A customer user can use the search results to disclose information from their "company" tickets (with the same CustomerID), even when the CustomerDisableCompanyTicketAccess setting is turned on.
CVE-2019-13421 1 Search-guard 1 Search Guard 2024-11-21 4.0 MEDIUM 4.9 MEDIUM
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
CVE-2019-13419 1 Search-guard 1 Search Guard 2024-11-21 5.0 MEDIUM 7.5 HIGH
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
CVE-2019-13417 1 Search-guard 1 Search Guard 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.
CVE-2019-13410 1 Topmeeting 1 Topmeeting 2024-11-21 5.0 MEDIUM 7.5 HIGH
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.
CVE-2019-13314 1 Redhat 1 Virt-bootstrap 2024-11-21 2.1 LOW 7.8 HIGH
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.