|
219511
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The aff…
|
NVD-CWE-noinfo
|
CVE-2019-20410
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219512
|
9.8 |
CRITICAL
Network
|
atlassian
|
jira_software_data_center jira
|
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a ser…
|
CWE-74
Injection
|
CVE-2019-20409
|
2024-11-21 13:38 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219513
|
8.1 |
HIGH
Network
|
intelliants
|
subrion
|
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenti…
|
CWE-352
Origin Validation Error
|
CVE-2019-20390
|
2024-11-21 13:38 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219514
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within mul…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20389
|
2024-11-21 13:38 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219515
|
6.1 |
MEDIUM
Network
|
atlassian
|
confluence_server
|
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-si…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20102
|
2024-11-21 13:38 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219516
|
4.8 |
MEDIUM
Network
|
netgear
|
rbr50_firmware rbk50_firmware rbs50_firmware
|
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20661
|
2024-11-21 13:38 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219517
|
4.8 |
MEDIUM
Network
|
netgear
|
rbr20_firmware rbs20_firmware rbk20_firmware rbr40_firmware rbs40_firmware rbk40_firmware rbr50_firmware rbs50_firmware rbk50_firmware
|
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20660
|
2024-11-21 13:38 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219518
|
7.2 |
HIGH
Network
|
netgear
|
r6400_firmware r6700_firmware r6900_firmware r7900_firmware
|
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R790…
|
CWE-77
Command Injection
|
CVE-2019-20659
|
2024-11-21 13:38 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219519
|
6.5 |
MEDIUM
Adjacent
|
netgear
|
fs728tlp_firmware gs105e_firmware gs105pe_firmware gs108e_firmware gs108pe_firmware gs110emx_firmware gs116e_firmware gs408epp_firmware gs808e_firmware gs810emx_firmware
|
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3…
|
NVD-CWE-noinfo
|
CVE-2019-20658
|
2024-11-21 13:38 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219520
|
7.8 |
HIGH
Local
|
netgear
|
xr500_firmware xr700_firmware
|
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.
|
CWE-77
Command Injection
|
CVE-2019-20655
|
2024-11-21 13:38 |
2020-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|