|
223281
|
4.8 |
MEDIUM
Network
|
zimbra
|
collaboration_server
|
Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12427
|
2024-11-21 13:22 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223282
|
6.5 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
|
NVD-CWE-noinfo
|
CVE-2019-12490
|
2024-11-21 13:22 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223283
|
5.5 |
MEDIUM
Local
|
hpe
|
superdome_flex_server_firmware
|
HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security …
|
CWE-20
Improper Input Validation
|
CVE-2019-11998
|
2024-11-21 13:22 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223284
|
6.1 |
MEDIUM
Network
|
hp
|
enhanced_internet_usage_manager
|
A potential security vulnerability has been identified in HPE enhanced Internet Usage Manager (eIUM) versions 8.3 and 9.0. The vulnerability could be used for unauthorized access to information via c…
|
CWE-79
Cross-site Scripting
|
CVE-2019-11997
|
2024-11-21 13:22 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223285
|
7.5 |
HIGH
Network
|
apache oracle
|
cxf flexcube_private_banking retail_order_broker communications_diameter_signaling_router communications_session_route_manager communications_session_report_manager communications_e…
|
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service.…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-12423
|
2024-11-21 13:22 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223286
|
4.8 |
MEDIUM
Network
|
apache
|
airflow
|
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain …
|
CWE-79
Cross-site Scripting
|
CVE-2019-12398
|
2024-11-21 13:22 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223287
|
7.5 |
HIGH
Network
|
apache oracle
|
kafka financial_services_analytical_applications_infrastructure banking_platform flexcube_universal_banking banking_virtual_account_management banking_corporate_lending_process_managem…
|
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-12399
|
2024-11-21 13:22 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223288
|
9.8 |
CRITICAL
Network
|
hp
|
simplivity_380_gen9_firmware simplivity_380_gen10_g_firmware simplivity_380_gen10_firmware simplivity_2600_gen10_firmware simplivity_omnicube_firmware simplivity_omnistack_for_dell_fir…
|
A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack…
|
CWE-22
Path Traversal
|
CVE-2019-11994
|
2024-11-21 13:22 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223289
|
7.5 |
HIGH
Network
|
hp
|
simplivity_380_gen9_firmware simplivity_380_gen10_g_firmware simplivity_380_gen10_firmware simplivity_2600_gen10_firmware simplivity_omnicube_firmware simplivity_omnistack_for_dell_fir…
|
A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack…
|
NVD-CWE-noinfo
|
CVE-2019-11993
|
2024-11-21 13:22 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223290
|
6.5 |
MEDIUM
Network
|
outsystems
|
outsystems
|
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemse…
|
CWE-352
Origin Validation Error
|
CVE-2019-12273
|
2024-11-21 13:22 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|