|
222501
|
7.5 |
HIGH
Network
|
rpyc_project
|
rpyc
|
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2019-16328
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222502
|
7.3 |
HIGH
Local
|
jetbrains
|
resharper
|
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-16407
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222503
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16171
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222504
|
4.3 |
MEDIUM
Network
|
enterprisedt
|
completeftp_server
|
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
|
CWE-327 CWE-532
Use of a Broken or Risky Cryptographic Algorithm Inclusion of Sensitive Information in Log Files
|
CVE-2019-16116
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222505
|
7.8 |
HIGH
Local
|
google
|
chrome_os
|
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a ma…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-16508
|
2024-11-21 13:30 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222506
|
7.5 |
HIGH
Network
|
golang debian opensuse fedoraproject redhat netapp
|
go debian_linux leap fedora openshift_container_platform enterprise_linux developer_tools enterprise_linux_eus cloud_insights_telegraf_agent
|
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16276
|
2024-11-21 13:30 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222507
|
4.8 |
MEDIUM
Network
|
xoops
|
xoops
|
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16684
|
2024-11-21 13:30 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222508
|
4.8 |
MEDIUM
Network
|
xoops
|
xoops
|
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16683
|
2024-11-21 13:30 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222509
|
6.1 |
MEDIUM
Network
|
gfi
|
kerio_control
|
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleartext credentials to an attacker via a login/?reason=failure…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16414
|
2024-11-21 13:30 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222510
|
9.8 |
CRITICAL
Network
|
plataformatec
|
simple_form
|
Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a user-supplied string is invoked as a method call.
|
CWE-20
Improper Input Validation
|
CVE-2019-16676
|
2024-11-21 13:30 |
2019-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|