|
223671
|
5.4 |
MEDIUM
Network
|
teampasswordmanager
|
team_password_manager
|
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19461
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223672
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
|
CWE-79
Cross-site Scripting
|
CVE-2019-19212
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223673
|
7.4 |
HIGH
Network
|
opcfoundation
|
ua-.netstandard netstandard.opc.ua
|
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle att…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-19135
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223674
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19211
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223675
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19210
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223676
|
7.5 |
HIGH
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-19209
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223677
|
9.8 |
CRITICAL
Network
|
codiad
|
codiad
|
Codiad Web IDE through 2.8.4 allows PHP Code injection.
|
CWE-94
Code Injection
|
CVE-2019-19208
|
2024-11-21 13:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223678
|
6.1 |
MEDIUM
Network
|
abacus
|
abacus
|
oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_0000 before prior to R4 (20.11.2019 Hotfix) allows Reflected Cross Site Scripting (XSS) via an error message.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19381
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223679
|
7.5 |
HIGH
Network
|
siemens
|
sinvr\/sivms_video_server
|
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2).…
|
-
|
CVE-2019-19299
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223680
|
7.5 |
HIGH
Network
|
siemens
|
sinvr\/sivms_video_server
|
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2). The streaming service (default port 5410/tcp) of t…
|
-
|
CVE-2019-19298
|
2024-11-21 13:34 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|