|
223491
|
5.5 |
MEDIUM
Local
|
brandy_project
|
brandy
|
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14663
|
2024-11-21 13:27 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223492
|
5.5 |
MEDIUM
Local
|
brandy_project
|
brandy
|
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14662
|
2024-11-21 13:27 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223493
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attri…
|
NVD-CWE-noinfo
|
CVE-2019-14654
|
2024-11-21 13:27 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223494
|
6.1 |
MEDIUM
Network
|
ipandao
|
editor.md
|
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14653
|
2024-11-21 13:27 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223495
|
8.8 |
HIGH
Network
|
comelitgroup
|
away_from_home
|
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to js/bridge.min.js and login.json. For example, an at…
|
CWE-269
Improper Privilege Management
|
CVE-2019-14453
|
2024-11-21 13:26 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223496
|
7.8 |
HIGH
Local
|
tianocore
|
edk2
|
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14584
|
2024-11-21 13:26 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223497
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to …
|
CWE-352
Origin Validation Error
|
CVE-2019-14481
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223498
|
8.8 |
HIGH
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
|
CWE-78
OS Command
|
CVE-2019-14479
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223499
|
5.4 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This d…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14478
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223500
|
6.5 |
MEDIUM
Network
|
adremsoft
|
netcrunch
|
AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-14476
|
2024-11-21 13:26 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|