|
221921
|
6.1 |
MEDIUM
Network
|
laravel-bjyblog_project
|
laravel-bjyblog
|
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17494
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221922
|
9.8 |
CRITICAL
Network
|
smartbear oracle
|
swagger_ui utilities_framework banking_digital_experience primavera_gateway banking_platform banking_apis
|
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltra…
|
CWE-352
Origin Validation Error
|
CVE-2019-17495
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221923
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17493
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221924
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17491
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221925
|
8.8 |
HIGH
Network
|
jnoj
|
jiangnan_online_judge
|
app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17490
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221926
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17489
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221927
|
6.1 |
MEDIUM
Network
|
b3log
|
symphony
|
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17488
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221928
|
8.8 |
HIGH
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-17386
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221929
|
9.8 |
CRITICAL
Network
|
nongnu debian canonical fedoraproject opensuse
|
libntlm debian_linux ubuntu_linux fedora leap backports_sle
|
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17455
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221930
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17454
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|