|
222141
|
8.8 |
HIGH
Network
|
enterprisedt
|
completeftp_server
|
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as…
|
CWE-77
Command Injection
|
CVE-2019-16864
|
2024-11-21 13:31 |
2022-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222142
|
5.4 |
MEDIUM
Network
|
solarwinds
|
web_help_desk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16961
|
2024-11-21 13:31 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222143
|
5.4 |
MEDIUM
Network
|
zohocorp
|
manageengine_desktop_central
|
Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16962
|
2024-11-21 13:31 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222144
|
5.4 |
MEDIUM
Network
|
solarwinds
|
web_help_desk
|
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16954
|
2024-11-21 13:31 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222145
|
5.4 |
MEDIUM
Network
|
solarwinds
|
web_help_desk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16960
|
2024-11-21 13:31 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222146
|
5.4 |
MEDIUM
Network
|
solarwinds
|
web_help_desk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16956
|
2024-11-21 13:31 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222147
|
7.5 |
HIGH
Network
|
matrixssl
|
matrixssl
|
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerabili…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16747
|
2024-11-21 13:31 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222148
|
6.5 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-16959
|
2024-11-21 13:31 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222149
|
5.4 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16957
|
2024-11-21 13:31 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222150
|
5.4 |
MEDIUM
Network
|
solarwinds
|
webhelpdesk
|
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16955
|
2024-11-21 13:31 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|