|
213821
|
6.1 |
MEDIUM
Network
|
jio
|
jmr1140_firmware
|
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7687
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213822
|
9.8 |
CRITICAL
Network
|
coship
|
rt3052_firmware rt3050_firmware wm3300_firmware rt7620_firmware
|
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST requ…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7564
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213823
|
6.1 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7541
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213824
|
8.1 |
HIGH
Network
|
kde opensuse fedoraproject
|
kauth leap backports fedora
|
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of …
|
CWE-20
Improper Input Validation
|
CVE-2019-7443
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213825
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7427
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213826
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7426
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213827
|
8.1 |
HIGH
Network
|
sonicwall
|
global_management_system
|
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-7476
|
2024-11-21 13:48 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213828
|
9.8 |
CRITICAL
Network
|
nice
|
engage
|
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7727
|
2024-11-21 13:48 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213829
|
9.8 |
CRITICAL
Network
|
auth0
|
auth0-wcf-service-jwt
|
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-7644
|
2024-11-21 13:48 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213830
|
9.0 |
CRITICAL
Network
|
cantemo
|
portal
|
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could en…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7551
|
2024-11-21 13:48 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|