|
212221
|
7.5 |
HIGH
Network
|
saet
|
tebe_small_firmware webapp
|
The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attackers to make several types of API calls without authentication, as demonstrated by…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9105
|
2024-11-21 13:50 |
2019-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212222
|
6.1 |
MEDIUM
Network
|
digitaldruid
|
hoteldruid
|
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8937
|
2024-11-21 13:50 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212223
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8929
|
2024-11-21 13:50 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212224
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userNam…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8928
|
2024-11-21 13:50 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212225
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emai…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8927
|
2024-11-21 13:50 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212226
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8926
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212227
|
4.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the…
|
CWE-22
Path Traversal
|
CVE-2019-8925
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212228
|
6.1 |
MEDIUM
Network
|
apachefriends
|
xampp
|
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8924
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212229
|
7.5 |
HIGH
Network
|
netapp fedoraproject opensuse hpe ntp
|
data_ontap clustered_data_ontap fedora leap hpux-ntp ntp
|
NTP through 4.2.8p12 has a NULL Pointer Dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8936
|
2024-11-21 13:50 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212230
|
9.8 |
CRITICAL
Network
|
apachefriends
|
xampp
|
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
|
CWE-89
SQL Injection
|
CVE-2019-8923
|
2024-11-21 13:50 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|