Search Results (322831 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-13983 1 Rangerstudio 1 Directus 7 Api 2024-11-21 N/A
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
CVE-2019-13982 1 Rangerstudio 1 Directus 7 2024-11-21 N/A
interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a preview.
CVE-2019-13981 1 Rangerstudio 1 Directus 7 Api 2024-11-21 N/A
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer.
CVE-2019-13980 1 Rangerstudio 1 Directus 7 Api 2024-11-21 N/A
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.
CVE-2019-13979 1 Rangerstudio 1 Directus 7 Api 2024-11-21 N/A
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
CVE-2019-13978 1 Ovidentia 1 Ovidentia 2024-11-21 N/A
Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.
CVE-2019-13977 1 Ovidentia 1 Ovidentia 2024-11-21 N/A
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=create, tg=site&item=4, tg=admdir&idx=mdb&id=1, tg=notes&idx=Create, tg=admfaqs&idx=Add, or tg=admoc&idx=addoc&item=.
CVE-2019-13976 1 Egain 1 Chat 2024-11-21 N/A
eGain Chat 15.0.3 allows unrestricted file upload.
CVE-2019-13975 1 Egain 1 Chat 2024-11-21 N/A
eGain Chat 15.0.3 allows HTML Injection.
CVE-2019-13974 1 Layerbb 1 Layerbb 2024-11-21 N/A
LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.
CVE-2019-13973 1 Layerbb 1 Layerbb 2024-11-21 N/A
LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used.
CVE-2019-13972 1 Layerbb 1 Layerbb 2024-11-21 N/A
LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997.
CVE-2019-13971 1 Otcms 1 Otcms 2024-11-21 N/A
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
CVE-2019-13970 1 Antsword Project 1 Antsword 2024-11-21 N/A
In antSword before 2.1.0, self-XSS in the database configuration leads to code execution via modules/database/asp/index.js, modules/database/custom/index.js, modules/database/index.js, or modules/database/php/index.js.
CVE-2019-13969 1 Metinfo 1 Metinfo 2024-11-21 N/A
Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.
CVE-2019-13967 1 Combodo 1 Itop 2024-11-21 7.5 High
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI. This only affects the community version.
CVE-2019-13966 1 Combodo 1 Itop 2024-11-21 6.1 Medium
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
CVE-2019-13965 1 Combodo 1 Itop 2024-11-21 6.1 Medium
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.
CVE-2019-13962 4 Canonical, Debian, Opensuse and 1 more 5 Ubuntu Linux, Debian Linux, Backports Sle and 2 more 2024-11-21 9.8 Critical
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
CVE-2019-13961 1 Flatcore 1 Flatcore 2024-11-21 N/A
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.