|
219611
|
6.1 |
MEDIUM
Network
|
determine
|
contract_lifecycle_management
|
An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters allows remote attack…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20154
|
2024-11-21 13:38 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219612
|
4.9 |
MEDIUM
Network
|
determine
|
contract_lifecycle_management
|
An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload…
|
CWE-611
XXE
|
CVE-2019-20153
|
2024-11-21 13:38 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219613
|
4.3 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this…
|
CWE-352
Origin Validation Error
|
CVE-2019-20077
|
2024-11-21 13:38 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219614
|
7.2 |
HIGH
Network
|
advanced_real_estate_script_project
|
advanced_real_estate_script
|
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-20337
|
2024-11-21 13:38 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219615
|
6.1 |
MEDIUM
Network
|
advanced_real_estate_script_project
|
advanced_real_estate_script
|
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20336
|
2024-11-21 13:38 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219616
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (a…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-20334
|
2024-11-21 13:38 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219617
|
9.8 |
CRITICAL
Network
|
fasterxml oracle debian netapp
|
jackson-databind retail_xstore_point_of_service primavera_unifier weblogic_server webcenter_portal enterprise_manager_base_platform communications_instant_messaging_server commun…
|
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-20330
|
2024-11-21 13:38 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219618
|
8.1 |
HIGH
Network
|
openlambda_project
|
openlambda
|
OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
|
CWE-346
Origin Validation Error
|
CVE-2019-20329
|
2024-11-21 13:38 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219619
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
MyBB before 1.8.22 allows an open redirect on login.
|
CWE-601
Open Redirect
|
CVE-2019-20225
|
2024-11-21 13:38 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219620
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20219
|
2024-11-21 13:38 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|