• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-11457
2019-10-09
N/A
8.8 HIGH
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
CVE-2019-11456
2019-04-26
N/A
8.8 HIGH
Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
CVE-2019-11455
2022-03-31
N/A
8.1 HIGH
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).
CVE-2019-11454
2022-03-31
N/A
6.1 MEDIUM
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is mishandled during an _viewlog operation.
CVE-2019-11452
2019-04-22
N/A
7.2 HIGH
whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection.
CVE-2019-11451
2019-04-22
N/A
7.2 HIGH
whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
CVE-2019-11450
2019-04-22
N/A
9.8 CRITICAL
whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
CVE-2019-1145
2020-08-24
N/A
8.8 HIGH
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1144, CVE-2019-1149, CVE-2019-1150, CVE-2019-1151, CVE-2019-1152.
CVE-2019-11449
2019-04-23
N/A
6.1 MEDIUM
I, Librarian 4.10 has XSS via the notes.php notes parameter.
CVE-2019-11448
2019-05-06
N/A
9.8 CRITICAL
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
« Previous 1 … 6,470 6,471 6,472 6,473 6,474 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE