|
223181
|
9.8 |
CRITICAL
Network
|
jetstream
|
jetselect
|
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plainte…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-13022
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223182
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-13021
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223183
|
7.5 |
HIGH
Network
|
cososys
|
endpoint_protector
|
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
|
CWE-74
Injection
|
CVE-2019-13285
|
2024-11-21 13:24 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223184
|
6.1 |
MEDIUM
Network
|
quantumcloud
|
simple_link_directory
|
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13463
|
2024-11-21 13:24 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223185
|
6.1 |
MEDIUM
Network
|
rainloop
|
webmail
|
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13389
|
2024-11-21 13:24 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223186
|
9.8 |
CRITICAL
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several functionalities of the w…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13202
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223187
|
9.8 |
CRITICAL
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attacker to cause a Denia…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13201
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223188
|
6.1 |
MEDIUM
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Reflected XSS. Successful exploitation of this vulnerability can lead to session hijacki…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13200
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223189
|
6.5 |
MEDIUM
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local a…
|
CWE-352
Origin Validation Error
|
CVE-2019-13199
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223190
|
6.1 |
MEDIUM
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Stored XSS. Successful exploitation of this vulnerability can lead to session hijacking …
|
CWE-79
Cross-site Scripting
|
CVE-2019-13198
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|