|
222721
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_desktop_central
|
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15510
|
2024-11-21 13:28 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222722
|
9.8 |
CRITICAL
Network
|
linbit
|
csync2
|
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
|
NVD-CWE-noinfo
|
CVE-2019-15522
|
2024-11-21 13:28 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222723
|
7.5 |
HIGH
Network
|
inextrix
|
astpp
|
An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA…
|
CWE-798 CWE-327
Use of Hard-coded Credentials Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-15075
|
2024-11-21 13:28 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222724
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit …
|
CWE-79
Cross-site Scripting
|
CVE-2019-15539
|
2024-11-21 13:28 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222725
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mobilefrontend
|
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15124
|
2024-11-21 13:28 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222726
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. Th…
|
CWE-287
Improper Authentication
|
CVE-2019-15299
|
2024-11-21 13:28 |
2020-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222727
|
4.8 |
MEDIUM
Network
|
cisco
|
dna_center
|
A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15253
|
2024-11-21 13:28 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222728
|
3.1 |
LOW
Adjacent
|
apple broadcom
|
iphone_os ipados mac_os_x bcm4389_firmware bcm43012_firmware bcm43013_firmware bcm4375_firmware bcm43752_firmware bcm4356_firmware
|
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper la…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-15126
|
2024-11-21 13:28 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222729
|
6.1 |
MEDIUM
Network
|
zimbra
|
collaboration_server
|
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15313
|
2024-11-21 13:28 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222730
|
6.1 |
MEDIUM
Network
|
cisco
|
finesse unified_contact_center_express
|
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. …
|
CWE-79
Cross-site Scripting
|
CVE-2019-15278
|
2024-11-21 13:28 |
2020-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|