|
223911
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13504
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223912
|
7.5 |
HIGH
Network
|
cesanta
|
mongoose
|
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13503
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223913
|
9.8 |
CRITICAL
Network
|
trape_project
|
trape
|
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
|
CWE-89
SQL Injection
|
CVE-2019-13489
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223914
|
6.1 |
MEDIUM
Network
|
trape_project
|
trape
|
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2019-13488
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223915
|
3.3 |
LOW
Local
|
cisofy debian fedoraproject
|
lynis debian_linux fedora
|
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis ser…
|
CWE-200
Information Exposure
|
CVE-2019-13033
|
2024-11-21 13:24 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223916
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users us…
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2019-13023
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223917
|
9.8 |
CRITICAL
Network
|
jetstream
|
jetselect
|
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plainte…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-13022
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223918
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-13021
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223919
|
7.5 |
HIGH
Network
|
cososys
|
endpoint_protector
|
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
|
CWE-74
Injection
|
CVE-2019-13285
|
2024-11-21 13:24 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223920
|
6.1 |
MEDIUM
Network
|
quantumcloud
|
simple_link_directory
|
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13463
|
2024-11-21 13:24 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|