|
222511
|
5.4 |
MEDIUM
Network
|
eleveo
|
call_recording
|
ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumber field in the (1) User Edit or (2) User Add form, (3) name field in the Role …
|
CWE-79
Cross-site Scripting
|
CVE-2019-18223
|
2024-11-21 13:32 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222512
|
8.8 |
HIGH
Network
|
dlink
|
dir-615_firmware
|
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-17525
|
2024-11-21 13:32 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222513
|
7.5 |
HIGH
Network
|
fortinet
|
fortiap-w2 fortiap-s fortiswitch fortianalyzer fortimanager
|
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-17657
|
2024-11-21 13:32 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222514
|
9.8 |
CRITICAL
Network
|
apache
|
dubbo
|
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance o…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17564
|
2024-11-21 13:32 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222515
|
7.5 |
HIGH
Network
|
apache oracle
|
netbeans graalvm
|
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and includin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-17561
|
2024-11-21 13:32 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222516
|
9.1 |
CRITICAL
Network
|
apache oracle
|
netbeans graalvm
|
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the downlo…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-17560
|
2024-11-21 13:32 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222517
|
5.4 |
MEDIUM
Network
|
netapp
|
oncommand_system_manager
|
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scr…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17276
|
2024-11-21 13:32 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222518
|
7.5 |
HIGH
Network
|
moxa
|
iologik_2512_firmware iologik_2512-t_firmware iologik_2512-hspa_firmware iologik_2512-hspa-t_firmware iologik_2512-wl1-eu_firmware iologik_2512-wl1-eu-t_firmware iologik_2512-wl1-us…
|
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to f…
|
NVD-CWE-noinfo
|
CVE-2019-18242
|
2024-11-21 13:32 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222519
|
9.8 |
CRITICAL
Network
|
apache debian
|
traffic_server debian_linux
|
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later version…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17565
|
2024-11-21 13:32 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222520
|
9.8 |
CRITICAL
Network
|
apache debian
|
traffic_server debian_linux
|
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17559
|
2024-11-21 13:32 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|