Exploit Database

153,618 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-15071 WRITEUP MEDIUM
MAIL2000 6.0-7.0 - Unauthenticated Stored Cross-Site Scripting via ACTION Parameter
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15071 WRITEUP MEDIUM
MAIL2000 6.0-7.0 - Unauthenticated Stored Cross-Site Scripting via ACTION Parameter
The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via ACTION parameter without authentication. The code can executed for any user accessing the page. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15072 WRITEUP MEDIUM
MAIL2000 6.0-7.0 - Cross-Site Scripting via Login Portal Parameters
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15072 WRITEUP MEDIUM
MAIL2000 6.0-7.0 - Cross-Site Scripting via Login Portal Parameters
The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15073 WRITEUP MEDIUM
Openfind MAIL2000 6.0-7.0 - Unauthenticated Open Redirect
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15073 WRITEUP MEDIUM
Openfind MAIL2000 6.0-7.0 - Unauthenticated Open Redirect
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
CVSS 6.1
CVE-2019-15129 WRITEUP MEDIUM
Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 - Unauthenticated Arbitrary File Access via Recruitment Module
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.
CVSS 5.3
CVE-2019-15130 WRITEUP CRITICAL
Humanica Humatrix 7 <=1.0.0.681 - Unauthenticated Arbitrary File Upload RCE via Recruitment Module
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the attacker can upload executable content (e.g., asp or aspx) for executing OS commands on the server.
CVSS 9.8
CVE-2019-15540 WRITEUP HIGH
libMirage 3.2.2 - Heap-Based Buffer Overflow in CSO Filter
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user.
CVSS 7.8
CVE-2019-15757 WRITEUP MEDIUM
libmirage 3.2.2 - NULL Pointer Dereference in NRG Parser
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
CVSS 6.5
CVE-2019-15848 WRITEUP MEDIUM
JetBrains TeamCity 2019.1-2019.1.1 - Cross-Site Scripting
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
CVSS 6.1
CVE-2019-15860 WRITEUP MEDIUM
Xpdf 2.00 - Memory Corruption
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVSS 5.5
CVE-2019-15947 WRITEUP HIGH
Bitcoin Core 0.18.0 - Info Disclosure
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command.
CVSS 7.5
CVE-2019-16088 WRITEUP MEDIUM
Xpdf 3.04 - Memory Corruption
Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
CVSS 5.5
CVE-2019-16106 WRITEUP HIGH
Humanica Humatrix <7 - Info Disclosure
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
CVSS 7.5
CVE-2019-16160 WRITEUP HIGH
MikroTik RouterOS < 6.45.5 - Unauthenticated Denial of Service via SMB Server Integer Underflow
An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to crash the service.
CVSS 7.5
CVE-2019-16261 WRITEUP CRITICAL
Tripp Lite PDUMH15AT and SU750XL <12.04.0053 <12.04.0052 - Unauthenticated Password Change and Power Control
Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NOTE: the vendor's position is that a newer firmware version, fixing this vulnerability, had already been released before this vulnerability report about 12.04.0053.
CVSS 9.1
CVE-2019-16307 WRITEUP MEDIUM
Fuji Xerox DocuShare <7.0.0.C1.609 - XSS
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).
CVSS 6.1
CVE-2019-16416 WRITEUP MEDIUM
HRworks 3.36.9 - Stored Cross-Site Scripting via Travel-Expense Report Purpose
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
CVSS 5.4
CVE-2019-16417 WRITEUP MEDIUM
HRworks FLOW 3.36.9 - Cross-Site Scripting via Travel-Expense Report Purpose
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
CVSS 5.4
CVE-2019-16791 WRITEUP MEDIUM
Postfix-mta-sts-resolver <0.5.1 - Info Disclosure
In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
CVSS 6.9
CVE-2019-17070 WRITEUP MEDIUM
LIQUID SPEECH BALLOON < 1.0.7 - Cross-Site Scripting
The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer.
CVSS 6.1
CVE-2019-17071 WRITEUP MEDIUM
Client Dash 2.1.4 - Cross-Site Scripting
The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
CVSS 6.1
CVE-2019-17072 WRITEUP CRITICAL
Contact Form Widget 1.0.9 - SQL Injection via all-query-page.php
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
CVSS 9.8
CVE-2019-17176 WRITEUP MEDIUM
Genesys eServices Chat 8.1.0-8.1.200.03 - Cross-Site Scripting via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).
CVSS 6.1