|
210891
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_encryption
|
Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software ap…
|
NVD-CWE-noinfo
|
CVE-2019-9694
|
2024-11-21 13:52 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210892
|
6.1 |
MEDIUM
Network
|
symantec
|
vip_enterprise_gateway
|
Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pa…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9696
|
2024-11-21 13:52 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210893
|
6.1 |
MEDIUM
Network
|
khanacademy fedoraproject
|
simple-markdown fedora
|
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9844
|
2024-11-21 13:52 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210894
|
7.5 |
HIGH
Network
|
kubernetes cncf netapp
|
kubernetes portmap cloud_insights
|
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-9946
|
2024-11-21 13:52 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210895
|
9.8 |
CRITICAL
Network
|
tongda2000
|
office_anywhere
|
An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9759
|
2024-11-21 13:52 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210896
|
7.5 |
HIGH
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
|
CWE-22
Path Traversal
|
CVE-2019-9922
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210897
|
6.5 |
MEDIUM
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-9921
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210898
|
8.8 |
HIGH
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.
|
NVD-CWE-noinfo
|
CVE-2019-9920
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210899
|
5.4 |
MEDIUM
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the mess…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9919
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210900
|
9.1 |
CRITICAL
Network
|
harmistechnology
|
je_messenger
|
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Sta…
|
CWE-89
SQL Injection
|
CVE-2019-9918
|
2024-11-21 13:52 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|