|
213511
|
6.1 |
MEDIUM
Network
|
pagerduty
|
rundeck
|
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6804
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213512
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6803
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213513
|
6.1 |
MEDIUM
Network
|
python
|
pypiserver
|
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2019-6802
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213514
|
6.1 |
MEDIUM
Network
|
kaine
|
wise_chat
|
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.
|
CWE-601
Open Redirect
|
CVE-2019-6780
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213515
|
8.1 |
HIGH
Network
|
chshcms
|
cscms
|
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
|
CWE-352
Origin Validation Error
|
CVE-2019-6779
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213516
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6777
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213517
|
7.5 |
HIGH
Network
|
mz-automation
|
libiec61850
|
An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by examples/server_example_goose/server_example_goose…
|
CWE-416
Use After Free
|
CVE-2019-6719
|
2024-11-21 13:47 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213518
|
- |
|
-
|
-
|
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
|
-
|
CVE-2019-6268
|
2024-11-21 13:46 |
2024-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213519
|
9.8 |
CRITICAL
Network
|
edge-core
|
ecs2020_firmware
|
Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.
|
CWE-77
Command Injection
|
CVE-2019-6288
|
2024-11-21 13:46 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213520
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierr…
|
CWE-20
Improper Input Validation
|
CVE-2019-6238
|
2024-11-21 13:46 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|