|
224231
|
6.1 |
MEDIUM
Network
|
trape_project
|
trape
|
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2019-13488
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224232
|
3.3 |
LOW
Local
|
cisofy debian fedoraproject
|
lynis debian_linux fedora
|
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis ser…
|
CWE-200
Information Exposure
|
CVE-2019-13033
|
2024-11-21 13:24 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224233
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users us…
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2019-13023
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224234
|
9.8 |
CRITICAL
Network
|
jetstream
|
jetselect
|
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plainte…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-13022
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224235
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-13021
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224236
|
7.5 |
HIGH
Network
|
cososys
|
endpoint_protector
|
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
|
CWE-74
Injection
|
CVE-2019-13285
|
2024-11-21 13:24 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224237
|
6.1 |
MEDIUM
Network
|
quantumcloud
|
simple_link_directory
|
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html i…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13463
|
2024-11-21 13:24 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224238
|
6.1 |
MEDIUM
Network
|
rainloop
|
webmail
|
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13389
|
2024-11-21 13:24 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224239
|
9.8 |
CRITICAL
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several functionalities of the w…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13202
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224240
|
9.8 |
CRITICAL
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attacker to cause a Denia…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13201
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|