|
224281
|
9.8 |
CRITICAL
Network
|
ros
|
ros-comm
|
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13445
|
2024-11-21 13:24 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224282
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u_ftp_server
|
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13182
|
2024-11-21 13:24 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224283
|
6.5 |
MEDIUM
Network
|
solarwinds
|
serv-u_ftp_server
|
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-13181
|
2024-11-21 13:24 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224284
|
7.5 |
HIGH
Network
|
atlassian
|
saml_single_sign_on
|
An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbuck…
|
NVD-CWE-noinfo
|
CVE-2019-13347
|
2024-11-21 13:24 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224285
|
6.5 |
MEDIUM
Adjacent
|
freeradius redhat opensuse
|
freeradius enterprise_linux leap
|
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks inf…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13456
|
2024-11-21 13:24 |
2019-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224286
|
7.5 |
HIGH
Network
|
naver
|
vaccine
|
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
|
CWE-22
Path Traversal
|
CVE-2019-13157
|
2024-11-21 13:24 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224287
|
5.4 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13081
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224288
|
5.4 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an adminis…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13080
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224289
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13079
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224290
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13078
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|