|
222141
|
7.1 |
HIGH
Local
|
trendmicro
|
antivirus\+_security_2020 internet_security_2020 maximum_security_2020 premium_security_2020
|
The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on af…
|
CWE-59
Link Following
|
CVE-2019-19693
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222142
|
6.1 |
MEDIUM
Network
|
trendmicro
|
apex_one
|
Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19692
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222143
|
4.9 |
MEDIUM
Network
|
trendmicro
|
apex_one officescan
|
A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must …
|
NVD-CWE-noinfo
|
CVE-2019-19691
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222144
|
6.1 |
MEDIUM
Network
|
ciprianmp
|
phpmychat-plus
|
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19908
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222145
|
6.5 |
MEDIUM
Network
|
codesys
|
sp_realtime_nt plcwinnt runtime_toolkit
|
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19789
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222146
|
9.0 |
CRITICAL
Network
|
webfactoryltd
|
301_redirects
|
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /a…
|
CWE-352 CWE-732
Origin Validation Error Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19915
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222147
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19910
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222148
|
8.8 |
HIGH
Network
|
sfu
|
open_journal_system
|
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an auth…
|
CWE-94 CWE-502
Code Injection Deserialization of Untrusted Data
|
CVE-2019-19909
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222149
|
9.8 |
CRITICAL
Network
|
kopano
|
groupware_core
|
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19907
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222150
|
7.5 |
HIGH
Network
|
cyrusimap debian canonical fedoraproject redhat apple apache
|
cyrus-sasl debian_linux ubuntu_linux fedora enterprise_linux jboss_enterprise_web_server mac_os_x enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution…
|
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by a…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-19906
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|