|
222571
|
6.5 |
MEDIUM
Adjacent
|
philips
|
veradius_unity_firmware pulsera_firmware endura_firmware
|
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewFo…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-18263
|
2024-11-21 13:32 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222572
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC …
|
NVD-CWE-Other
|
CVE-2019-17440
|
2024-11-21 13:32 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222573
|
9.8 |
CRITICAL
Network
|
joomsky
|
js_jobs
|
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfiel…
|
CWE-89
SQL Injection
|
CVE-2019-17527
|
2024-11-21 13:32 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222574
|
7.8 |
HIGH
Local
|
arista
|
cloudvision_portal
|
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configl…
|
NVD-CWE-noinfo
|
CVE-2019-18181
|
2024-11-21 13:32 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222575
|
8.8 |
HIGH
Network
|
eclipse
|
che
|
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and …
|
CWE-352
Origin Validation Error
|
CVE-2019-17633
|
2024-11-21 13:32 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222576
|
7.8 |
HIGH
Local
|
pronestor
|
planner
|
An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control i…
|
NVD-CWE-noinfo
|
CVE-2019-17390
|
2024-11-21 13:32 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222577
|
5.4 |
MEDIUM
Network
|
ge
|
s2020_firmware s2020g_firmware
|
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that …
|
CWE-79
Cross-site Scripting
|
CVE-2019-18267
|
2024-11-21 13:32 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222578
|
9.8 |
CRITICAL
Network
|
advantech
|
diaganywhere
|
In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service listening on the TCP port. Successful exploitatio…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18257
|
2024-11-21 13:32 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222579
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17337
|
2024-11-21 13:32 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222580
|
6.5 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains multiple vulnerabilities that theoretically allow an …
|
NVD-CWE-noinfo
|
CVE-2019-17336
|
2024-11-21 13:32 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|