|
223481
|
6.1 |
MEDIUM
Network
|
scadabr
|
scadabr
|
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16344
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223482
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16417
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223483
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16416
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223484
|
7.4 |
HIGH
Network
|
twitter
|
twitter_kit
|
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16263
|
2024-11-21 13:30 |
2019-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223485
|
6.5 |
MEDIUM
Network
|
kslabs
|
ksweb
|
KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
|
CWE-22
Path Traversal
|
CVE-2019-16198
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223486
|
7.5 |
HIGH
Network
|
rpyc_project
|
rpyc
|
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2019-16328
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223487
|
7.3 |
HIGH
Local
|
jetbrains
|
resharper
|
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-16407
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223488
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16171
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223489
|
4.3 |
MEDIUM
Network
|
enterprisedt
|
completeftp_server
|
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
|
CWE-327 CWE-532
Use of a Broken or Risky Cryptographic Algorithm Inclusion of Sensitive Information in Log Files
|
CVE-2019-16116
|
2024-11-21 13:30 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223490
|
7.8 |
HIGH
Local
|
google
|
chrome_os
|
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a ma…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-16508
|
2024-11-21 13:30 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|