|
219301
|
6.1 |
MEDIUM
Network
|
treasuryxpress
|
treasuryxpress
|
An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed throughout the application. A malicious paylo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20152
|
2024-11-21 13:38 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219302
|
6.1 |
MEDIUM
Network
|
treasuryxpress
|
treasuryxpress
|
An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed by the application's administrator(s). A mali…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20151
|
2024-11-21 13:38 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219303
|
6.5 |
MEDIUM
Network
|
treasuryxpress
|
treasuryxpress
|
In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them. Using functionality within the application and a malicious host, it is possible to force th…
|
NVD-CWE-noinfo
|
CVE-2019-20150
|
2024-11-21 13:38 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219304
|
7.8 |
HIGH
Local
|
abbyy
|
finereader
|
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.
|
CWE-59
Link Following
|
CVE-2019-20383
|
2024-11-21 13:38 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219305
|
7.8 |
HIGH
Local
|
atlassian
|
jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-20419
|
2024-11-21 13:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219306
|
6.5 |
MEDIUM
Network
|
atlassian
|
jira_software_data_center jira
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wik…
|
NVD-CWE-noinfo
|
CVE-2019-20418
|
2024-11-21 13:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219307
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira
|
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vul…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-20408
|
2024-11-21 13:38 |
2020-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219308
|
4.8 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration fe…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20416
|
2024-11-21 13:38 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219309
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected version…
|
CWE-352
Origin Validation Error
|
CVE-2019-20415
|
2024-11-21 13:38 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219310
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20414
|
2024-11-21 13:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|