|
223141
|
7.5 |
HIGH
Network
|
atlassian
|
saml_single_sign_on
|
An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbuck…
|
NVD-CWE-noinfo
|
CVE-2019-13347
|
2024-11-21 13:24 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223142
|
6.5 |
MEDIUM
Adjacent
|
freeradius redhat opensuse
|
freeradius enterprise_linux leap
|
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks inf…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13456
|
2024-11-21 13:24 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223143
|
7.5 |
HIGH
Network
|
naver
|
vaccine
|
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
|
CWE-22
Path Traversal
|
CVE-2019-13157
|
2024-11-21 13:24 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223144
|
5.4 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13081
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223145
|
5.4 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an adminis…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13080
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223146
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13079
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223147
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13078
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223148
|
6.1 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows an attacker to create a malicious link in order t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13077
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223149
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13076
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223150
|
6.1 |
MEDIUM
Network
|
sahipro
|
sahi_pro
|
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, An…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13066
|
2024-11-21 13:24 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|