|
223471
|
9.8 |
CRITICAL
Network
|
softwareag oracle apache netapp atlassian
|
quartz flexcube_investor_servicing retail_xstore_point_of_service flexcube_private_banking primavera_unifier retail_integration_bus retail_back_office webcenter_sites fusion_m…
|
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
|
CWE-611
XXE
|
CVE-2019-13990
|
2024-11-21 13:25 |
2019-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223472
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server via recursive…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13955
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223473
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13954
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223474
|
7.8 |
HIGH
Local
|
gnu debian
|
patch debian_linux
|
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed edit…
|
CWE-78
OS Command
|
CVE-2019-13638
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223475
|
7.5 |
HIGH
Network
|
openldap canonical debian opensuse f5 apple oracle
|
openldap ubuntu_linux debian_linux leap traffix_signaling_delivery_controller mac_os_x solaris zfs_storage_appliance_kit blockchain_platform
|
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtai…
|
NVD-CWE-noinfo
|
CVE-2019-13565
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223476
|
9.8 |
CRITICAL
Network
|
exim debian
|
exim debian_linux
|
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo…
|
CWE-19
Data Processing Errors
|
CVE-2019-13917
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223477
|
7.2 |
HIGH
Network
|
ajdg
|
adrotate
|
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-13570
|
2024-11-21 13:25 |
2019-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223478
|
9.8 |
CRITICAL
Network
|
icegram
|
email_subscribers_\&_newsletters
|
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to …
|
CWE-89
SQL Injection
|
CVE-2019-13569
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223479
|
6.5 |
MEDIUM
Adjacent
|
arduino
|
arduino_firmware
|
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
|
NVD-CWE-noinfo
|
CVE-2019-13991
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223480
|
7.8 |
HIGH
Local
|
dpic_project
|
dpic
|
dpic 2019.06.20 has a Stack-based Buffer Overflow in the wfloat() function in main.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13989
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|