• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-13979
2019-07-22
N/A
8.8 HIGH
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
CVE-2019-13978
2019-07-27
N/A
8.8 HIGH
Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.
CVE-2019-13977
2019-07-27
N/A
5.4 MEDIUM
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.
CVE-2019-13976
2019-09-05
N/A
9.8 CRITICAL
eGain Chat 15.0.3 allows unrestricted file upload.
CVE-2019-13975
2020-08-24
N/A
6.1 MEDIUM
eGain Chat 15.0.3 allows HTML Injection.
CVE-2019-13974
2019-07-19
N/A
8.8 HIGH
LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.
CVE-2019-13973
2019-07-19
N/A
9.8 CRITICAL
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.
CVE-2019-13972
2019-07-19
N/A
6.1 MEDIUM
LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997.
CVE-2019-13971
2019-07-22
N/A
6.1 MEDIUM
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
CVE-2019-13970
2019-07-22
N/A
6.1 MEDIUM
In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.
« Previous 1 … 6,251 6,252 6,253 6,254 6,255 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE