|
220151
|
6.5 |
MEDIUM
Network
|
djangoproject debian canonical fedoraproject
|
django debian_linux ubuntu_linux fedora
|
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defa…
|
CWE-74
Injection
|
CVE-2019-3498
|
2024-11-21 13:42 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220152
|
7.5 |
HIGH
Network
|
mcafee
|
mcafee_web_gateway
|
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.
|
CWE-20
Improper Input Validation
|
CVE-2019-3581
|
2024-11-21 13:42 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220153
|
10.0 |
CRITICAL
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-3905
|
2024-11-21 13:42 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220154
|
7.8 |
HIGH
Local
|
sqla_yaml_fixtures_project
|
sqla_yaml_fixtures
|
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
|
CWE-94
Code Injection
|
CVE-2019-3575
|
2024-11-21 13:42 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220155
|
4.4 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dl…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-3701
|
2024-11-21 13:42 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220156
|
7.5 |
HIGH
Network
|
openrefine
|
openrefine
|
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
|
CWE-22
Path Traversal
|
CVE-2019-3580
|
2024-11-21 13:42 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220157
|
9.8 |
CRITICAL
Network
|
bijiadao
|
waimai_super_cms
|
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
|
CWE-89
SQL Injection
|
CVE-2019-3577
|
2024-11-21 13:42 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220158
|
9.8 |
CRITICAL
Network
|
inxedu_project
|
inxedu
|
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.us…
|
CWE-89
SQL Injection
|
CVE-2019-3576
|
2024-11-21 13:42 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220159
|
6.5 |
MEDIUM
Network
|
libming
|
libming
|
An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png command-line program. Because this is associated wi…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-3572
|
2024-11-21 13:42 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220160
|
4.8 |
MEDIUM
Network
|
ougc_awards_project
|
ougc_awards
|
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards page or in a user profile.
|
CWE-79
Cross-site Scripting
|
CVE-2019-3501
|
2024-11-21 13:42 |
2019-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|