|
221911
|
6.1 |
MEDIUM
Network
|
corehr
|
core_portal
|
CoreHR Core Portal before 27.0.7 allows stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18221
|
2024-11-21 13:32 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221912
|
7.5 |
HIGH
Network
|
golang debian fedoraproject redhat opensuse arista
|
go debian_linux fedora enterprise_linux developer_tools enterprise_linux_server leap mos eos cloudvision_portal terminattr
|
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client …
|
CWE-436
Interpretation Conflict
|
CVE-2019-17596
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221913
|
6.7 |
MEDIUM
Local
|
teamviewer
|
teamviewer
|
A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397), 12.0.181268 (fixed in 12.0.214399), 13.2.36215 (fixed in 13.2.36216), and 14.6…
|
CWE-426
Untrusted Search Path
|
CVE-2019-18196
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221914
|
7.5 |
HIGH
Network
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, an attacker is able to eavesdrop on sensitive data suc…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18201
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221915
|
9.8 |
CRITICAL
Network
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, they are prone to keystroke injection attacks.
|
NVD-CWE-noinfo
|
CVE-2019-18200
|
2024-11-21 13:32 |
2019-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221916
|
6.6 |
MEDIUM
Physics
|
fujitsu
|
lx390_firmware
|
An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, and because of password-based authentication, they are…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-18199
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221917
|
6.1 |
MEDIUM
Network
|
dormsystem_project
|
dormsystem
|
tonyy dormsystem through 1.3 allows DOM XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17581
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221918
|
6.5 |
MEDIUM
Network
|
xml_language_server_project eclipse theia_xml_extension_project
|
xml_server_project wild_web_developer theia_xml_extension
|
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote …
|
CWE-22
Path Traversal
|
CVE-2019-18212
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221919
|
8.8 |
HIGH
Network
|
xml_language_server_project eclipse theia_xml_extension_project
|
xml_server_project wild_web_developer theia_xml_extension
|
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with…
|
CWE-611
XXE
|
CVE-2019-18213
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221920
|
6.1 |
MEDIUM
Network
|
hexo-admin_project
|
hexo-admin
|
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17606
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|