|
222481
|
6.1 |
MEDIUM
Network
|
ant.design
|
ant_design_pro
|
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18350
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222482
|
6.1 |
MEDIUM
Network
|
python
|
python
|
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the fir…
|
CWE-74
Injection
|
CVE-2019-18348
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222483
|
9.8 |
CRITICAL
Network
|
online_grading_system_project
|
online_grading_system
|
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room,…
|
CWE-89
SQL Injection
|
CVE-2019-18344
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222484
|
6.5 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware gateway
|
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and …
|
NVD-CWE-noinfo
|
CVE-2019-18177
|
2024-11-21 13:32 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222485
|
5.4 |
MEDIUM
Network
|
digitalalertsystems
|
dasdec_ii_firmware one-net_se_firmware dasdec_i_firmware one-net_firmware dasdec_iii_firmware
|
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH usernam…
|
-
|
CVE-2019-18265
|
2024-11-21 13:32 |
2022-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222486
|
5.3 |
MEDIUM
Network
|
apache fedoraproject oracle
|
http_server fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit
|
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing …
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-17567
|
2024-11-21 13:32 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222487
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios fortiproxy
|
A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated r…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17656
|
2024-11-21 13:32 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222488
|
9.8 |
CRITICAL
Network
|
advantech
|
spectre_rt_ert351_firmware
|
Advantech Spectre RT ERT351 Versions 5.1.3 and prior has insufficient login authentication parameters required for the web application may allow an attacker to gain full access using a brute-force pa…
|
-
|
CVE-2019-18235
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222489
|
6.1 |
MEDIUM
Network
|
advantech
|
spectre_rt_ert351_firmware
|
In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error response, allowing attackers to use a reflected XSS attack.
|
-
|
CVE-2019-18233
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222490
|
7.5 |
HIGH
Network
|
advantech
|
spectre_rt_ert351_firmware
|
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.
|
-
|
CVE-2019-18231
|
2024-11-21 13:32 |
2021-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|