|
223221
|
6.1 |
MEDIUM
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13274
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223222
|
9.8 |
CRITICAL
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb paramet…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13273
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223223
|
8.8 |
HIGH
Adjacent
|
edimax
|
br-6208ac_v1_firmware
|
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as bro…
|
NVD-CWE-noinfo
|
CVE-2019-13271
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223224
|
4.3 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.js…
|
CWE-22
Path Traversal
|
CVE-2019-13237
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223225
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms
|
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13236
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223226
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13235
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223227
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13234
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223228
|
10.0 |
CRITICAL
Network
|
trms
|
tightrope_media_carousel
|
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-13020
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223229
|
5.5 |
MEDIUM
Local
|
obdev
|
little_snitch
|
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately…
|
CWE-459
Incomplete Cleanup
|
CVE-2019-13014
|
2024-11-21 13:24 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223230
|
5.5 |
MEDIUM
Local
|
obdev
|
little_snitch
|
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any…
|
CWE-862
Missing Authorization
|
CVE-2019-13013
|
2024-11-21 13:24 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|