|
223971
|
5.4 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an adminis…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13080
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223972
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13079
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223973
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13078
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223974
|
6.1 |
MEDIUM
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows an attacker to create a malicious link in order t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13077
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223975
|
8.8 |
HIGH
Network
|
quest
|
kace_systems_management_appliance
|
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected co…
|
CWE-89
SQL Injection
|
CVE-2019-13076
|
2024-11-21 13:24 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223976
|
6.1 |
MEDIUM
Network
|
sahipro
|
sahi_pro
|
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, An…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13066
|
2024-11-21 13:24 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223977
|
7.5 |
HIGH
Network
|
hinet
|
gpon_firmware
|
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0…
|
NVD-CWE-noinfo
|
CVE-2019-13412
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223978
|
7.5 |
HIGH
Network
|
topmeeting
|
topmeeting
|
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.
|
CWE-200
Information Exposure
|
CVE-2019-13410
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223979
|
9.8 |
CRITICAL
Network
|
topmeeting
|
topmeeting
|
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databa…
|
CWE-89
SQL Injection
|
CVE-2019-13409
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223980
|
9.8 |
CRITICAL
Network
|
hinet
|
gpon_firmware
|
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: …
|
NVD-CWE-noinfo
|
CVE-2019-13411
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|