|
223641
|
7.5 |
HIGH
Network
|
apache oracle
|
netbeans graalvm
|
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and includin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-17561
|
2024-11-21 13:32 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223642
|
9.1 |
CRITICAL
Network
|
apache oracle
|
netbeans graalvm
|
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the downlo…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-17560
|
2024-11-21 13:32 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223643
|
5.4 |
MEDIUM
Network
|
netapp
|
oncommand_system_manager
|
OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scr…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17276
|
2024-11-21 13:32 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223644
|
7.5 |
HIGH
Network
|
moxa
|
iologik_2512_firmware iologik_2512-t_firmware iologik_2512-hspa_firmware iologik_2512-hspa-t_firmware iologik_2512-wl1-eu_firmware iologik_2512-wl1-eu-t_firmware iologik_2512-wl1-us…
|
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to f…
|
NVD-CWE-noinfo
|
CVE-2019-18242
|
2024-11-21 13:32 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223645
|
9.8 |
CRITICAL
Network
|
apache debian
|
traffic_server debian_linux
|
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later version…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17565
|
2024-11-21 13:32 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223646
|
9.8 |
CRITICAL
Network
|
apache debian
|
traffic_server debian_linux
|
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17559
|
2024-11-21 13:32 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223647
|
8.8 |
HIGH
Network
|
fortinet
|
fortimanager
|
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH)…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-17654
|
2024-11-21 13:32 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223648
|
8.8 |
HIGH
Network
|
fortinet
|
fortisiem
|
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated …
|
CWE-352
Origin Validation Error
|
CVE-2019-17653
|
2024-11-21 13:32 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223649
|
9.8 |
CRITICAL
Network
|
fortinet
|
forticlient
|
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executabl…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-17658
|
2024-11-21 13:32 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223650
|
8.1 |
HIGH
Network
|
eclipse
|
theia
|
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs,…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-17636
|
2024-11-21 13:32 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|