• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-16661
2019-09-23
N/A
5.4 MEDIUM
Ogma CMS 0.5 has XSS via creation of a new blog.
CVE-2019-16660
2019-09-23
N/A
8.8 HIGH
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
CVE-2019-1666
2020-10-05
N/A
5.3 MEDIUM
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by sending crafted requests to the Graphite service. A successful exploit could allow the attacker to retrieve any statistics from the Graphite service. Versions prior to 3.5(2a) are affected.
CVE-2019-16659
2019-09-23
N/A
8.8 HIGH
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
CVE-2019-16658
2019-09-23
N/A
8.8 HIGH
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
CVE-2019-16657
2019-09-23
N/A
6.1 MEDIUM
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
CVE-2019-16656
2021-07-21
N/A
9.8 CRITICAL
joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.
CVE-2019-16655
2021-07-21
N/A
7.5 HIGH
joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
CVE-2019-16653
2021-07-21
N/A
8.8 HIGH
An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges.
CVE-2019-16652
2021-07-21
N/A
7.2 HIGH
The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands.
« Previous 1 … 6,012 6,013 6,014 6,015 6,016 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE