Show filters
440 Total Results
Displaying 261-270 of 440
Sort by:
Attacker Value
Unknown

CVE-2019-20442

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.
Attacker Value
Unknown

CVE-2019-20440

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.
Attacker Value
Unknown

CVE-2019-20330

Disclosure Date: January 03, 2020 (last updated February 21, 2025)
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Attacker Value
Unknown

CVE-2013-4868

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Karotz API 12.07.19.00: Session Token Information Disclosure
Attacker Value
Unknown

CVE-2019-4609

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
IBM API Connect 2018.4.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 168510.
Attacker Value
Unknown

CVE-2019-4444

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
IBM API Connect 2018.1 through 2018.4.1.7 Developer Portal's user registration page does not disable password autocomplete. An attacker with access to the browser instance and local system credentials can steal the credentials used for registration. IBM X-Force ID: 163453.
Attacker Value
Unknown

CVE-2019-19595

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
Attacker Value
Unknown

CVE-2019-19594

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
Attacker Value
Unknown

CVE-2019-15631

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2019-10216

Disclosure Date: November 27, 2019 (last updated November 08, 2023)
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.