|
221091
|
5.3 |
MEDIUM
Network
|
rapid7
|
nexpose
|
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser featur…
|
CWE-200
Information Exposure
|
CVE-2019-5640
|
2024-11-21 13:45 |
2021-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221092
|
7.5 |
HIGH
Network
|
rapid7
|
metasploit
|
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can eit…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-5645
|
2024-11-21 13:45 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221093
|
6.5 |
MEDIUM
Adjacent
|
fortinet
|
fortios
|
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5591
|
2024-11-21 13:45 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221094
|
6.1 |
MEDIUM
Network
|
graphpaperpress
|
sell_media
|
A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parame…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6112
|
2024-11-21 13:45 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221095
|
9.8 |
CRITICAL
Network
|
panasonic
|
video_insight_vms
|
Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2019-5997
|
2024-11-21 13:45 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221096
|
7.5 |
HIGH
Network
|
netapp
|
fas26x0_firmware fas27x0_firmware fas8200_firmware aff_c190_firmware aff_a200_firmware aff_a220_firmware aff_a300_firmware
|
Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS).
|
NVD-CWE-noinfo
|
CVE-2019-5500
|
2024-11-21 13:45 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221097
|
9.8 |
CRITICAL
Network
|
accellion
|
file_transfer_appliance
|
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').
|
CWE-78
OS Command
|
CVE-2019-5623
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221098
|
9.8 |
CRITICAL
Network
|
accellion
|
file_transfer_appliance
|
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-5622
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221099
|
7.8 |
HIGH
Local
|
abbs_software_audio_media_player_project
|
abbs_software_audio_media_player
|
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5621
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221100
|
9.8 |
CRITICAL
Network
|
hitachienergy
|
microscada_pro_sys600
|
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5620
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|