|
222801
|
7.5 |
HIGH
Network
|
python
|
python
|
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE:…
|
NVD-CWE-noinfo CWE-682
Incorrect Calculation
|
CVE-2019-17514
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222802
|
5.3 |
MEDIUM
Network
|
kirona
|
dynamic_resource_scheduling
|
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive informa…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-17503
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222803
|
8.8 |
HIGH
Network
|
compal
|
ch7465lg_firmware
|
The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execut…
|
CWE-78
OS Command
|
CVE-2019-17499
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222804
|
6.5 |
MEDIUM
Network
|
tracker-software
|
pdf-xchange_editor
|
Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link t…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-17497
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222805
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17496
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222806
|
6.1 |
MEDIUM
Network
|
laravel-bjyblog_project
|
laravel-bjyblog
|
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17494
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222807
|
9.8 |
CRITICAL
Network
|
smartbear oracle
|
swagger_ui utilities_framework banking_digital_experience primavera_gateway banking_platform banking_apis
|
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltra…
|
CWE-352
Origin Validation Error
|
CVE-2019-17495
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222808
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17493
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222809
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17491
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222810
|
8.8 |
HIGH
Network
|
jnoj
|
jiangnan_online_judge
|
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17490
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|