|
223821
|
6.5 |
MEDIUM
Network
|
imgix
|
imgix
|
Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-13655
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223822
|
9.8 |
CRITICAL
Network
|
vsourz
|
advanced_cf7_db
|
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute a…
|
CWE-89
SQL Injection
|
CVE-2019-13571
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223823
|
7.4 |
HIGH
Network
|
oneidentity
|
cloud_access_manager
|
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-13498
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223824
|
6.1 |
MEDIUM
Network
|
wikindx_project
|
wikindx
|
A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via the PagingStart para…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13588
|
2024-11-21 13:25 |
2019-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223825
|
9.8 |
CRITICAL
Network
|
softwareag oracle apache netapp atlassian
|
quartz flexcube_investor_servicing retail_xstore_point_of_service flexcube_private_banking primavera_unifier retail_integration_bus retail_back_office webcenter_sites fusion_m…
|
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
|
CWE-611
XXE
|
CVE-2019-13990
|
2024-11-21 13:25 |
2019-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223826
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server via recursive…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13955
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223827
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13954
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223828
|
7.8 |
HIGH
Local
|
gnu debian
|
patch debian_linux
|
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed edit…
|
CWE-78
OS Command
|
CVE-2019-13638
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223829
|
7.5 |
HIGH
Network
|
openldap canonical debian opensuse f5 apple oracle
|
openldap ubuntu_linux debian_linux leap traffix_signaling_delivery_controller mac_os_x solaris zfs_storage_appliance_kit blockchain_platform
|
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtai…
|
NVD-CWE-noinfo
|
CVE-2019-13565
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223830
|
9.8 |
CRITICAL
Network
|
exim debian
|
exim debian_linux
|
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo…
|
CWE-19
Data Processing Errors
|
CVE-2019-13917
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|