|
221971
|
9.1 |
CRITICAL
Network
|
bender
|
com465ip_firmware com465dp_firmware com465id_firmware cp700_firmware cp907_firmware cp915_firmware
|
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorizati…
|
CWE-862
Missing Authorization
|
CVE-2019-19885
|
2024-11-21 13:35 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221972
|
7.5 |
HIGH
Network
|
ise
|
smart_connect_knx_vaillant
|
ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-19643
|
2024-11-21 13:35 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221973
|
7.5 |
HIGH
Network
|
jetbrains
|
upsource
|
In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
|
NVD-CWE-noinfo
|
CVE-2019-19704
|
2024-11-21 13:35 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221974
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19935
|
2024-11-21 13:35 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221975
|
7.8 |
HIGH
Local
|
videolan
|
vlc_media_player
|
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted i…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-19721
|
2024-11-21 13:35 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221976
|
7.2 |
HIGH
Network
|
centreon
|
centreon
|
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguratio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19699
|
2024-11-21 13:35 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221977
|
4.8 |
MEDIUM
Network
|
intland
|
codebeamer
|
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19913
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221978
|
4.8 |
MEDIUM
Network
|
intland
|
codebeamer
|
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19912
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221979
|
9.8 |
CRITICAL
Network
|
x-plane
|
x-plane
|
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network pac…
|
CWE-78
OS Command
|
CVE-2019-19606
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221980
|
9.8 |
CRITICAL
Network
|
x-plane
|
x-plane
|
X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19605
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|