|
212881
|
6.1 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7541
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212882
|
8.1 |
HIGH
Network
|
kde opensuse fedoraproject
|
kauth leap backports fedora
|
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of …
|
CWE-20
Improper Input Validation
|
CVE-2019-7443
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212883
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7427
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212884
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7426
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212885
|
8.1 |
HIGH
Network
|
sonicwall
|
global_management_system
|
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-7476
|
2024-11-21 13:48 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212886
|
9.8 |
CRITICAL
Network
|
nice
|
engage
|
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers t…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7727
|
2024-11-21 13:48 |
2019-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212887
|
9.8 |
CRITICAL
Network
|
auth0
|
auth0-wcf-service-jwt
|
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-7644
|
2024-11-21 13:48 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212888
|
9.0 |
CRITICAL
Network
|
cantemo
|
portal
|
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could en…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7551
|
2024-11-21 13:48 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212889
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Aut…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-7361
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212890
|
7.8 |
HIGH
Local
|
autodesk
|
advance_steel autocad autocad_architecture autocad_electrical autocad_lt autocad_map_3d autocad_mechanical autocad_mep autocad_p\&id autocad_plant_3d civil_3d
|
An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 201…
|
CWE-416
Use After Free
|
CVE-2019-7360
|
2024-11-21 13:48 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|