|
221881
|
5.4 |
MEDIUM
Network
|
tibco
|
ebx_add-ons
|
The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site script…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17332
|
2024-11-21 13:32 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221882
|
5.4 |
MEDIUM
Network
|
tibco
|
ebx_add-ons
|
The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17331
|
2024-11-21 13:32 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221883
|
9.6 |
CRITICAL
Network
|
tibco
|
ebx
|
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and un…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17330
|
2024-11-21 13:32 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221884
|
7.5 |
HIGH
Network
|
hitachi
|
device_manager replication_manager tiered_storage_manager infrastructure_analytics_advisor tuning_manager
|
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-17360
|
2024-11-21 13:32 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221885
|
8.8 |
HIGH
Network
|
admincolumns
|
admin_columns
|
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula code as his first o…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-17661
|
2024-11-21 13:32 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221886
|
7.2 |
HIGH
Network
|
tmaxsoft
|
jeus
|
JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input parameter check when uploading installation file in administration web page. That leads…
|
CWE-22
Path Traversal
|
CVE-2019-17327
|
2024-11-21 13:32 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221887
|
8.8 |
HIGH
Network
|
eyecomms
|
eyecms
|
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-17605
|
2024-11-21 13:32 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221888
|
4.3 |
MEDIUM
Network
|
eyecomms
|
eyecms
|
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV,…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-17604
|
2024-11-21 13:32 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221889
|
7.5 |
HIGH
Network
|
lightbend
|
play_framework
|
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when co…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-17598
|
2024-11-21 13:32 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221890
|
7.5 |
HIGH
Network
|
amazon
|
freertos\+fat
|
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definit…
|
CWE-416
Use After Free
|
CVE-2019-18178
|
2024-11-21 13:32 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|