|
224521
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19935
|
2024-11-21 13:35 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224522
|
7.8 |
HIGH
Local
|
videolan
|
vlc_media_player
|
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted i…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-19721
|
2024-11-21 13:35 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224523
|
7.2 |
HIGH
Network
|
centreon
|
centreon
|
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguratio…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19699
|
2024-11-21 13:35 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224524
|
4.8 |
MEDIUM
Network
|
intland
|
codebeamer
|
In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19913
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224525
|
4.8 |
MEDIUM
Network
|
intland
|
codebeamer
|
In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19912
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224526
|
9.8 |
CRITICAL
Network
|
x-plane
|
x-plane
|
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network pac…
|
CWE-78
OS Command
|
CVE-2019-19606
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224527
|
9.8 |
CRITICAL
Network
|
x-plane
|
x-plane
|
X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19605
|
2024-11-21 13:35 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224528
|
2.7 |
LOW
Network
|
netgear
|
gs728tps_firmware
|
On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration panel can access part of the web panel, bypassing authentication.
|
NVD-CWE-noinfo
|
CVE-2019-19964
|
2024-11-21 13:35 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224529
|
4.3 |
MEDIUM
Network
|
arxes-tolina
|
arxes-tolina
|
arxes-tolina 3.0.0 allows User Enumeration.
|
CWE-200
Information Exposure
|
CVE-2019-19677
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224530
|
9.6 |
CRITICAL
Network
|
arxes-tolina
|
arxes-tolina
|
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlz…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-19676
|
2024-11-21 13:35 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|