|
211071
|
5.4 |
MEDIUM
Network
|
fiberhomegroup
|
an5506-04-f_firmware
|
FiberHome an5506-04-f RP2669 devices have XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9556
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211072
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9554
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211073
|
6.1 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9553
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211074
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9207
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211075
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9206
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211076
|
8.8 |
HIGH
Network
|
unity3d
|
unity_editor
|
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2019-9197
|
2024-11-21 13:51 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211077
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicating an app accessed the user's location. This could…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-9464
|
2024-11-21 13:51 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211078
|
6.8 |
MEDIUM
Physics
|
apple
|
iphone_3gs
|
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-9536
|
2024-11-21 13:51 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211079
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User in…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2019-9467
|
2024-11-21 13:51 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211080
|
6.5 |
MEDIUM
Network
|
darktrace
|
enterprise_immune_system
|
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
|
CWE-352
Origin Validation Error
|
CVE-2019-9597
|
2024-11-21 13:51 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|