|
223681
|
9.8 |
CRITICAL
Network
|
saltstack debian opensuse canonical
|
salt debian_linux leap ubuntu_linux
|
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoin…
|
CWE-77
Command Injection
|
CVE-2019-17361
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223682
|
6.1 |
MEDIUM
Network
|
apache oracle
|
cxf flexcube_private_banking retail_order_broker communications_element_manager communications_session_report_manager communications_session_route_manager commerce_guided_search
|
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17573
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223683
|
5.3 |
MEDIUM
Network
|
linux debian netapp
|
linux_kernel debian_linux a700s_firmware 8300_firmware 8700_firmware a400_firmware h610s_firmware cloud_backup steelstore_cloud_integrated_storage data_availability_service…
|
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet rel…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-18282
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223684
|
6.5 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauthorized tag data when viewing analysis data referen…
|
NVD-CWE-Other
|
CVE-2019-18275
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223685
|
4.8 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, which may allow invalid input to be introduced.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18273
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223686
|
8.8 |
HIGH
Network
|
osisoft
|
pi_vision
|
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.
|
CWE-352
Origin Validation Error
|
CVE-2019-18271
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223687
|
4.7 |
MEDIUM
Local
|
osisoft
|
pi_vision
|
In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. T…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-18244
|
2024-11-21 13:32 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223688
|
7.8 |
HIGH
Local
|
totalav
|
totalav_2020
|
TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.
|
NVD-CWE-noinfo
|
CVE-2019-18194
|
2024-11-21 13:32 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223689
|
4.3 |
MEDIUM
Network
|
otrs debian opensuse
|
otrs debian_linux leap backports_sle
|
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent…
|
NVD-CWE-noinfo
|
CVE-2019-18179
|
2024-11-21 13:32 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223690
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-859_firmware dir-822_firmware dir-823_firmware dir-865l_firmware dir-868l_firmware dir-869_firmware dir-880l_firmware dir-890l_firmware dir-890r_firmware dir-885l_firmw…
|
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted…
|
CWE-78
OS Command
|
CVE-2019-17621
|
2024-11-21 13:32 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|