|
222111
|
7.5 |
HIGH
Network
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data suc…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18201
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222112
|
9.8 |
CRITICAL
Network
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, they are prone to keystroke injection attacks.
|
NVD-CWE-noinfo
|
CVE-2019-18200
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222113
|
6.6 |
MEDIUM
Physics
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18199
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222114
|
6.1 |
MEDIUM
Network
|
dormsystem_project
|
dormsystem
|
tonyy dormsystem through 1.3 allows DOM XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17581
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222115
|
6.5 |
MEDIUM
Network
|
xml_language_server_project eclipse theia_xml_extension_project
|
xml_server_project wild_web_developer theia_xml_extension
|
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote …
|
CWE-22
Path Traversal
|
CVE-2019-18212
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222116
|
8.8 |
HIGH
Network
|
xml_language_server_project eclipse theia_xml_extension_project
|
xml_server_project wild_web_developer theia_xml_extension
|
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with…
|
CWE-611
XXE
|
CVE-2019-18213
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222117
|
6.1 |
MEDIUM
Network
|
hexo-admin_project
|
hexo-admin
|
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17606
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222118
|
4.3 |
MEDIUM
Network
|
qt debian
|
qtbase debian_linux
|
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-18281
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222119
|
8.8 |
HIGH
Network
|
online_grading_system_project
|
online_grading_system
|
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into exe…
|
CWE-352
Origin Validation Error
|
CVE-2019-18280
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222120
|
7.8 |
HIGH
Local
|
videolan
|
vlc_media_player
|
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the …
|
NVD-CWE-noinfo
|
CVE-2019-18278
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|