|
222631
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14953
|
2024-11-21 13:27 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222632
|
9.8 |
CRITICAL
Network
|
jetbrains
|
teamcity
|
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
|
CWE-22
Path Traversal
|
CVE-2019-15039
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222633
|
5.9 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http connection.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14954
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222634
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14952
|
2024-11-21 13:27 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222635
|
6.1 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14752
|
2024-11-21 13:27 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222636
|
7.5 |
HIGH
Network
|
mit fedoraproject
|
kerberos_5 fedora
|
A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated use…
|
-
|
CVE-2019-14844
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222637
|
8.8 |
HIGH
Network
|
glpi-project
|
glpi
|
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password…
|
CWE-200
Information Exposure
|
CVE-2019-14666
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222638
|
9.8 |
CRITICAL
Network
|
gigastone
|
smart_battery_a4_firmware
|
An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 . An attacker can bypass authentication without modifying device…
|
NVD-CWE-noinfo
|
CVE-2019-15069
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222639
|
9.8 |
CRITICAL
Network
|
gigastone
|
smart_battery_a4_firmware
|
A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7.9 allows an attacker to get/reset administrator’s password without any authent…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15068
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222640
|
9.8 |
CRITICAL
Network
|
gigastone
|
smart_battery_a2-25de_firmware
|
An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware version ?<= SECFS-2013-10-16-13:42:58-629c30ee-60c68be6. An attacker can bypas…
|
NVD-CWE-noinfo
|
CVE-2019-15067
|
2024-11-21 13:27 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|