|
221871
|
7.2 |
HIGH
Network
|
netapp
|
ontap_select_deploy_administration_utility
|
All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges.
|
NVD-CWE-noinfo
|
CVE-2019-17272
|
2024-11-21 13:32 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221872
|
7.8 |
HIGH
Local
|
zohocorp
|
manageengine_firewall_analyzer manageengine_opmanager
|
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17421
|
2024-11-21 13:32 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221873
|
7.8 |
HIGH
Local
|
comodo
|
comodo_internet_security
|
An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially u…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-18215
|
2024-11-21 13:32 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221874
|
4.6 |
MEDIUM
Physics
|
espressif
|
esp32-d0wd_firmware esp32-d2wd_firmware esp32-s0wd_firmware esp32-pico-d4_firmware
|
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-17391
|
2024-11-21 13:32 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221875
|
9.8 |
CRITICAL
Network
|
fujielectric
|
v-server
|
In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18240
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221876
|
6.1 |
MEDIUM
Network
|
adenion
|
blog2social
|
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17550
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221877
|
6.1 |
MEDIUM
Network
|
cleantalk
|
spam_protection\ _antispam\ _firewall
|
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code vi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17515
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221878
|
8.8 |
HIGH
Network
|
phoenix
|
securecore_technology
|
In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application to gain elevated privileges. Adverse impacts are limited to the Windows enviro…
|
NVD-CWE-noinfo
|
CVE-2019-18279
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221879
|
5.4 |
MEDIUM
Network
|
technicolor
|
tc7300.b0_firmware
|
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a c…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17524
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221880
|
5.4 |
MEDIUM
Network
|
technicolor
|
tc7300.b0_firmware
|
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17523
|
2024-11-21 13:32 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|