Search Results (323679 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17634 1 Eclipse 1 Memory Analyzer 2024-11-21 9.0 Critical
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could be specially crafted, or could come from a crafted application or from an application processing malicious data. The vulnerability is present whena report is generated and opened from the Memory Analyzer graphical user interface, or when a report generated in batch mode is then opened in Memory Analyzer or by a web browser. The vulnerability could possibly allow code execution on the local system whenthe report is opened in Memory Analyzer.
CVE-2019-17633 1 Eclipse 1 Che 2024-11-21 8.8 High
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.
CVE-2019-17632 1 Eclipse 1 Jetty 2024-11-21 6.1 Medium
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
CVE-2019-17631 2 Eclipse, Redhat 9 Openj9, Enterprise Linux, Enterprise Linux Desktop and 6 more 2024-11-21 9.1 Critical
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
CVE-2019-17630 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 4.8 Medium
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
CVE-2019-17629 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 4.8 Medium
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
CVE-2019-17627 1 Yalehome 1 Yale Bluetooth Key 2024-11-21 6.5 Medium
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the authentication key via simple computations on the hex digits of a valid authentication request. This affects the Yale ZEN-R lock and unspecified other locks.
CVE-2019-17626 2 Redhat, Reportlab 3 Enterprise Linux, Rhel E4s, Reportlab 2024-11-21 9.8 Critical
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
CVE-2019-17625 1 Rambox 1 Rambox 2024-11-21 9.0 Critical
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
CVE-2019-17624 1 X.org 1 X Server 2024-11-21 7.8 High
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application crash) or possibly have unspecified other impact. Note: It is disputed if the X.Org X Server is involved or if there is a stack overflow.
CVE-2019-17613 1 Qibosoft 1 Qibosoft 2024-11-21 9.8 Critical
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.
CVE-2019-17612 1 74cms 1 74cms 2024-11-21 7.2 High
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17611 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
CVE-2019-17610 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
CVE-2019-17609 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
CVE-2019-17608 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.
CVE-2019-17607 1 Hongcms Project 1 Hongcms 2024-11-21 6.1 Medium
HongCMS 3.0.0 has XSS via the install/index.php servername parameter.
CVE-2019-17606 1 Hexo-admin Project 1 Hexo-admin 2024-11-21 6.1 Medium
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
CVE-2019-17605 1 Eyecomms 1 Eyecms 2024-11-21 8.8 High
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.
CVE-2019-17604 1 Eyecomms 1 Eyecms 2024-11-21 4.3 Medium
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV, phone number, and all other personal information) by changing the value of the candidate id (the id parameter).