|
222421
|
6.1 |
MEDIUM
Network
|
avg
|
anti-virus
|
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18654
|
2024-11-21 13:33 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222422
|
6.1 |
MEDIUM
Network
|
avast
|
antivirus
|
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to e…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18653
|
2024-11-21 13:33 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222423
|
5.4 |
MEDIUM
Network
|
jitbit
|
.net_forum
|
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18636
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222424
|
7.2 |
HIGH
Network
|
technicolor
|
td5130v2_firmware
|
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remot…
|
CWE-78
OS Command
|
CVE-2019-18396
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222425
|
5.3 |
MEDIUM
Network
|
yandex
|
clickhouse
|
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
|
CWE-74
Injection
|
CVE-2019-18657
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222426
|
6.1 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18656
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222427
|
9.8 |
CRITICAL
Network
|
ipswitch
|
moveit_transfer
|
In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-18465
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222428
|
9.8 |
CRITICAL
Network
|
ipswitch
|
moveit_transfer
|
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that …
|
CWE-89
SQL Injection
|
CVE-2019-18464
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222429
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-18369
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222430
|
7.3 |
HIGH
Network
|
jetbrains
|
toolbox
|
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
|
NVD-CWE-noinfo
|
CVE-2019-18368
|
2024-11-21 13:33 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|