|
218841
|
6.1 |
MEDIUM
Network
|
graphpaperpress
|
sell_media
|
A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parame…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6112
|
2024-11-21 13:45 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218842
|
9.8 |
CRITICAL
Network
|
panasonic
|
video_insight_vms
|
Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2019-5997
|
2024-11-21 13:45 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218843
|
7.5 |
HIGH
Network
|
netapp
|
fas26x0_firmware fas27x0_firmware fas8200_firmware aff_c190_firmware aff_a200_firmware aff_a220_firmware aff_a300_firmware
|
Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS).
|
NVD-CWE-noinfo
|
CVE-2019-5500
|
2024-11-21 13:45 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218844
|
9.8 |
CRITICAL
Network
|
accellion
|
file_transfer_appliance
|
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').
|
CWE-78
OS Command
|
CVE-2019-5623
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218845
|
9.8 |
CRITICAL
Network
|
accellion
|
file_transfer_appliance
|
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-5622
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218846
|
7.8 |
HIGH
Local
|
abbs_software_audio_media_player_project
|
abbs_software_audio_media_player
|
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5621
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218847
|
9.8 |
CRITICAL
Network
|
hitachienergy
|
microscada_pro_sys600
|
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-5620
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218848
|
9.8 |
CRITICAL
Network
|
aasync
|
aasync
|
AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5619
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218849
|
7.8 |
HIGH
Local
|
a-pdf
|
wav_to_mp3
|
A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5618
|
2024-11-21 13:45 |
2020-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218850
|
9.8 |
CRITICAL
Network
|
freebsd netapp
|
freebsd clustered_data_ontap
|
In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in access…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2019-5614
|
2024-11-21 13:45 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|