Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

17,305 results · Page 343/347
3.3
CVE-2018-20936

cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).

3.3
CVE-2018-20939

cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging

3.3
CVE-2018-20940

cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of bac

3.3
CVE-2018-20944

cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).

3.3
CVE-2018-20946

cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archi

3.3
CVE-2017-18397

cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).

3.3
CVE-2017-18421

cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).

3.3
CVE-2017-18422

In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).

3.3
CVE-2017-18423

In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).

3.3
CVE-2017-18424

In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).

3.3
CVE-2017-18427

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

3.3
CVE-2017-18429

In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).

3.3
CVE-2017-18458

cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).

3.3
CVE-2016-10772

cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).

3.3
CVE-2019-10994

Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow

3.3
CVE-2019-14671

Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of p

3.3
CVE-2016-10796

cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).

3.3
CVE-2019-5301

Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An

3.3
CVE-2019-13511

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A m

3.3
CVE-2019-13512

Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an a

3.3
CVE-2019-11806

OX App Suite 7.10.1 and earlier has Insecure Permissions.

3.3
CVE-2019-4132

IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rath

3.3
CVE-2019-15919

An issue was discovered in the Linux kernel before 5.0.10. SMB2_write in fs/cifs/smb2pdu.c has a use-after-free.

3.3
CVE-2019-0353

Under certain conditions SAP Business One client (B1_ON_HANA, SAP-M-BO), before versions 9.2 and 9.3, allows an attacker

3.3
CVE-2018-9581

In WiFi, the RSSI value and SSID information is broadcast as part of android.net.wifi.RSSI_CHANGE and android.net.wifi.S

3.3
CVE-2019-9277

In the proc filesystem, there is a possible information disclosure due to log information disclosure. This could lead to

3.3
CVE-2019-9280

In keyguard, there is a possible escalation of privilege due to improper permission checks. This could lead to a local b

3.3
CVE-2019-9292

In the Activity Manager service, there is a possible information disclosure due to a confused deputy. This could lead to

3.3
CVE-2019-9351

In SyncStatusObserver, there is a possible bypass for operating system protections that isolate user profiles from each

3.3
CVE-2019-9364

In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to lo

3.3
CVE-2019-9377

In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each

3.3
CVE-2019-9438

In the Package Manager service, there is a possible information disclosure due to a confused deputy. This could lead to

3.3
CVE-2019-9440

In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure

3.3
CVE-2019-4112

IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on

3.3
CVE-2019-10433

Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can

3.3
CVE-2019-17052

ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce

3.3
CVE-2019-17053

ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does

3.3
CVE-2019-17054

atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforc

3.3
CVE-2019-17055

base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not

3.3
CVE-2019-17056

llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce

3.3
CVE-2019-17263

In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap

3.3
CVE-2019-17264

In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-base

3.3
CVE-2019-17401

libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_locati

3.3
CVE-2019-10450

Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins m

3.3
CVE-2019-4398

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a l

3.3
CVE-2019-4395

IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive informat

3.3
CVE-2013-1945

ruby193 uses an insecure LD_LIBRARY_PATH setting.

3.3
CVE-2016-4983

A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

3.3
CVE-2019-5642

Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server

3.3
CVE-2009-3614

liboping 1.3.2 allows users reading arbitrary files upon the local system.

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started