|
224191
|
5.4 |
MEDIUM
Network
|
sitecore
|
experience_platform
|
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13493
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224192
|
6.8 |
MEDIUM
Physics
|
linux
|
linux_kernel
|
In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation o…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13631
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224193
|
9.8 |
CRITICAL
Network
|
fanucamerica
|
robotics_virtual_robot_controller
|
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP request.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13585
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224194
|
5.3 |
MEDIUM
Network
|
fanucamerica
|
robotics_virtual_robot_controller
|
The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-13584
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224195
|
9.8 |
CRITICAL
Network
|
tp-link
|
archer_c1200_firmware
|
CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and earlier is prone to a stack-based buffer overflow, which allows a remote attacke…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13614
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224196
|
9.8 |
CRITICAL
Network
|
tp-link
|
archer_c1200_firmware
|
CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180502 rel.45702 (EU) and earlier is prone to a stack-based buffer overflow, which…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13613
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224197
|
6.5 |
MEDIUM
Network
|
libsdl fedoraproject debian opensuse
|
libsdl fedora debian_linux leap
|
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13626
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224198
|
9.8 |
CRITICAL
Network
|
foliovision
|
fv_flowplayer_video_player
|
A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker …
|
CWE-89
SQL Injection
|
CVE-2019-13573
|
2024-11-21 13:25 |
2019-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224199
|
9.1 |
CRITICAL
Network
|
nsa
|
ghidra
|
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
|
CWE-611
XXE
|
CVE-2019-13625
|
2024-11-21 13:25 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224200
|
9.8 |
CRITICAL
Network
|
onosproject
|
onos
|
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
|
CWE-19
Data Processing Errors
|
CVE-2019-13624
|
2024-11-21 13:25 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|