Show filters
545 Total Results
Displaying 241-250 of 545
Sort by:
Attacker Value
Unknown
CVE-2019-14451
Disclosure Date: October 25, 2019 (last updated November 27, 2024)
RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.
0
Attacker Value
Unknown
CVE-2019-18212
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.
0
Attacker Value
Unknown
CVE-2019-18213
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java.
0
Attacker Value
Unknown
CVE-2015-9498
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
0
Attacker Value
Unknown
CVE-2019-12568
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.
0
Attacker Value
Unknown
CVE-2019-5480
Disclosure Date: September 03, 2019 (last updated November 27, 2024)
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
0
Attacker Value
Unknown
CVE-2019-15824
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
0
Attacker Value
Unknown
CVE-2019-15823
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
0
Attacker Value
Unknown
CVE-2019-15826
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
0
Attacker Value
Unknown
CVE-2019-15822
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
0