|
219681
|
7.5 |
HIGH
Network
|
sync
|
oxygen_xml_editor oxygen_xml_author oxygen_xml_developer
|
Oxygen XML Editor 21.1.1 allows XXE to read any file.
|
CWE-611
XXE
|
CVE-2019-20191
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219682
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
|
NVD-CWE-noinfo
|
CVE-2019-20491
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219683
|
9.8 |
CRITICAL
Network
|
quest
|
kace_systems_management
|
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
|
CWE-78
OS Command
|
CVE-2019-20504
|
2024-11-21 13:38 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219684
|
6.5 |
MEDIUM
Network
|
usrsctp_project debian canonical
|
usrsctp debian_linux ubuntu_linux
|
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20503
|
2024-11-21 13:38 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219685
|
7.5 |
HIGH
Network
|
echatserver
|
easy_chat_server
|
An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-20502
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219686
|
3.5 |
LOW
Adjacent
|
qemu opensuse debian canonical
|
qemu leap debian_linux ubuntu_linux
|
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-20382
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219687
|
7.8 |
HIGH
Local
|
dlink
|
dwl-2600ap_firmware
|
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.…
|
CWE-78
OS Command
|
CVE-2019-20501
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219688
|
7.8 |
HIGH
Local
|
dlink
|
dwl-2600ap_firmware
|
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admi…
|
CWE-78
OS Command
|
CVE-2019-20500
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219689
|
7.8 |
HIGH
Local
|
dlink
|
dwl-2600ap_firmware
|
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the a…
|
CWE-78
OS Command
|
CVE-2019-20499
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219690
|
8.8 |
HIGH
Network
|
testlink
|
testlink
|
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) re…
|
CWE-89
SQL Injection
|
CVE-2019-20107
|
2024-11-21 13:38 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|