|
211861
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emai…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8927
|
2024-11-21 13:50 |
2019-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211862
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8926
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211863
|
4.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the…
|
CWE-22
Path Traversal
|
CVE-2019-8925
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211864
|
6.1 |
MEDIUM
Network
|
apachefriends
|
xampp
|
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8924
|
2024-11-21 13:50 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211865
|
7.5 |
HIGH
Network
|
netapp fedoraproject opensuse hpe ntp
|
data_ontap clustered_data_ontap fedora leap hpux-ntp ntp
|
NTP through 4.2.8p12 has a NULL Pointer Dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8936
|
2024-11-21 13:50 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211866
|
9.8 |
CRITICAL
Network
|
apachefriends
|
xampp
|
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
|
CWE-89
SQL Injection
|
CVE-2019-8923
|
2024-11-21 13:50 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211867
|
8.1 |
HIGH
Network
|
ellucian
|
banner_web_tailor banner_enterprise_identity_services
|
An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, …
|
CWE-287 CWE-362
Improper Authentication Race Condition
|
CVE-2019-8978
|
2024-11-21 13:50 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211868
|
6.5 |
MEDIUM
Network
|
bosch
|
divar_ip_2000_firmware divar_ip_5000_firmware video_recording_manager video_management_system
|
A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files o…
|
CWE-22
Path Traversal
|
CVE-2019-8952
|
2024-11-21 13:50 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211869
|
6.1 |
MEDIUM
Network
|
bosch
|
divar_ip_2000_firmware divar_ip_5000_firmware video_recording_manager video_management_system
|
An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary …
|
CWE-601
Open Redirect
|
CVE-2019-8951
|
2024-11-21 13:50 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211870
|
7.5 |
HIGH
Network
|
solarwinds
|
dameware_mini_remote_control
|
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9017
|
2024-11-21 13:50 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|