|
223691
|
9.8 |
CRITICAL
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-13452
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223692
|
9.8 |
CRITICAL
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-13451
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223693
|
6.1 |
MEDIUM
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13274
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223694
|
9.8 |
CRITICAL
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb paramet…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13273
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223695
|
8.8 |
HIGH
Adjacent
|
edimax
|
br-6208ac_v1_firmware
|
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as bro…
|
NVD-CWE-noinfo
|
CVE-2019-13271
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223696
|
4.3 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.js…
|
CWE-22
Path Traversal
|
CVE-2019-13237
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223697
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms
|
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13236
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223698
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13235
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223699
|
6.1 |
MEDIUM
Network
|
alkacon
|
opencms_apollo_template
|
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13234
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223700
|
10.0 |
CRITICAL
Network
|
trms
|
tightrope_media_carousel
|
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-13020
|
2024-11-21 13:24 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|