|
224311
|
7.5 |
HIGH
Network
|
netgear
|
wnr2000_firmware
|
An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) wireless router. A SOAP request sent in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-5055
|
2024-11-21 13:44 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224312
|
7.5 |
HIGH
Network
|
netgear
|
wnr2000_firmware
|
An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-5054
|
2024-11-21 13:44 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224313
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSS. This was addressed in GitLab 12.1.2, 12.0.4, and 11.11.6.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5471
|
2024-11-21 13:44 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224314
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5467
|
2024-11-21 13:44 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224315
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.…
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2019-5463
|
2024-11-21 13:44 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224316
|
3.5 |
LOW
Adjacent
|
gitlab
|
gitlab
|
An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This…
|
CWE-20
Improper Input Validation
|
CVE-2019-5461
|
2024-11-21 13:44 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224317
|
6.5 |
MEDIUM
Network
|
epignosishq
|
efront_lms
|
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, res…
|
CWE-89
SQL Injection
|
CVE-2019-5070
|
2024-11-21 13:44 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224318
|
8.8 |
HIGH
Network
|
epignosishq
|
efront_lms
|
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker c…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-5069
|
2024-11-21 13:44 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224319
|
5.3 |
MEDIUM
Network
|
blynk
|
blynk-library
|
An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially crafted packet can cause an unterminated strncpy, resulting in info…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5065
|
2024-11-21 13:44 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224320
|
8.8 |
HIGH
Network
|
aspose
|
aspose.words
|
An exploitable Stack Based Buffer Overflow vulnerability exists in the EnumMetaInfo function of Aspose Aspose.Words library, version 18.11.0.0. A specially crafted doc file can cause a stack-based bu…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5041
|
2024-11-21 13:44 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|