|
222911
|
7.5 |
HIGH
Network
|
nazgul
|
nostromo_nhttpd
|
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16279
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222912
|
9.8 |
CRITICAL
Network
|
nazgul
|
nostromo_nhttpd
|
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16278
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222913
|
7.8 |
HIGH
Local
|
eset
|
cyber_security endpoint_antivirus endpoint_security
|
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.
|
CWE-269
Improper Privilege Management
|
CVE-2019-16519
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222914
|
6.1 |
MEDIUM
Network
|
scadabr
|
scadabr
|
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16344
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222915
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16417
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222916
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16416
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222917
|
7.4 |
HIGH
Network
|
twitter
|
twitter_kit
|
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16263
|
2024-11-21 13:30 |
2019-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222918
|
6.5 |
MEDIUM
Network
|
kslabs
|
ksweb
|
KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
|
CWE-22
Path Traversal
|
CVE-2019-16198
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222919
|
7.5 |
HIGH
Network
|
rpyc_project
|
rpyc
|
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2019-16328
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222920
|
7.3 |
HIGH
Local
|
jetbrains
|
resharper
|
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-16407
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|