|
211081
|
9.8 |
CRITICAL
Network
|
miniblog.core_project
|
miniblog.core
|
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs wr…
|
CWE-20
Improper Input Validation
|
CVE-2019-9845
|
2024-11-21 13:52 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211082
|
7.5 |
HIGH
Network
|
xmltooling_project canonical opensuse
|
xmltooling ubuntu_linux leap
|
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-9628
|
2024-11-21 13:52 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211083
|
8.8 |
HIGH
Network
|
dasannetworks
|
h660rm_firmware
|
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web inter…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-9976
|
2024-11-21 13:52 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211084
|
7.5 |
HIGH
Network
|
dasannetworks
|
h660rm_firmware
|
DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-9975
|
2024-11-21 13:52 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211085
|
9.1 |
CRITICAL
Network
|
dasannetworks
|
h660rm_firmware
|
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or cra…
|
CWE-306 CWE-862
Missing Authentication for Critical Function Missing Authorization
|
CVE-2019-9974
|
2024-11-21 13:52 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211086
|
9.8 |
CRITICAL
Network
|
jfrog
|
artifactory
|
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifacto…
|
NVD-CWE-noinfo
|
CVE-2019-9733
|
2024-11-21 13:52 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211087
|
7.8 |
HIGH
Local
|
symantec
|
endpoint_encryption
|
Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software ap…
|
NVD-CWE-noinfo
|
CVE-2019-9694
|
2024-11-21 13:52 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211088
|
6.1 |
MEDIUM
Network
|
symantec
|
vip_enterprise_gateway
|
Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pa…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9696
|
2024-11-21 13:52 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211089
|
6.1 |
MEDIUM
Network
|
khanacademy fedoraproject
|
simple-markdown fedora
|
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9844
|
2024-11-21 13:52 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211090
|
7.5 |
HIGH
Network
|
kubernetes cncf netapp
|
kubernetes portmap cloud_insights
|
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-9946
|
2024-11-21 13:52 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|