|
219001
|
5.3 |
MEDIUM
Network
|
senecajs
|
seneca
|
Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-5483
|
2024-11-21 13:45 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219002
|
5.3 |
MEDIUM
Network
|
statichttpserver_project
|
statichttpserver
|
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
|
CWE-22
Path Traversal
|
CVE-2019-5480
|
2024-11-21 13:45 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219003
|
7.5 |
HIGH
Network
|
larvit
|
larvitbase
|
An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2019-5479
|
2024-11-21 13:45 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219004
|
5.5 |
MEDIUM
Local
|
xilinx
|
zynq_ultrascale\+_mpsoc_firmware zynq_ultrascale\+_rfsoc_firmware
|
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able to modify the control fields of the boot image leading to an incorrect secure bo…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-5478
|
2024-11-21 13:45 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219005
|
8.8 |
HIGH
Network
|
sonatype
|
nexus_repository_manager
|
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.
|
CWE-78
OS Command
|
CVE-2019-5475
|
2024-11-21 13:45 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219006
|
7.5 |
HIGH
Network
|
onkyo
|
tx-nr686_firmware
|
Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to read arbitrary files via a .. (dot dot) and %2f to the default URI.
|
CWE-22
Path Traversal
|
CVE-2019-6113
|
2024-11-21 13:45 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219007
|
7.5 |
HIGH
Network
|
freebsd netapp
|
freebsd clustered_data_ontap
|
In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driv…
|
CWE-362
Race Condition
|
CVE-2019-5612
|
2024-11-21 13:45 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219008
|
7.5 |
HIGH
Network
|
freebsd netapp
|
freebsd clustered_data_ontap
|
In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check…
|
CWE-20
Improper Input Validation
|
CVE-2019-5611
|
2024-11-21 13:45 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219009
|
7.5 |
HIGH
Network
|
freebsd netapp
|
freebsd clustered_data_ontap
|
In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp librar…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5610
|
2024-11-21 13:45 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219010
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5609
|
2024-11-21 13:45 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|