Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2019
PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-12-31
PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-12-31
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
CVSS Score
6.1
EPSS Score
0.009
Published
2019-12-31
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
CVSS Score
6.1
EPSS Score
0.013
Published
2019-12-31
FiberHome an5506-04-f RP2669 devices have XSS.
CVSS Score
5.4
EPSS Score
0.004
Published
2019-12-31
An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial of service (daemon crash) via a 0xffff datalen field value.
CVSS Score
7.5
EPSS Score
0.011
Published
2019-12-31
The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.
CVSS Score
4.3
EPSS Score
0.002
Published
2019-12-31
A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for privilege escalation by dumping the local machine's SAM and SYSTEM database files, and possibly remote code execution.
CVSS Score
7.5
EPSS Score
0.125
Published
2019-12-31
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
CVSS Score
8.8
EPSS Score
0.031
Published
2019-12-31
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
CVSS Score
6.1
EPSS Score
0.003
Published
2019-12-31


Contact Us

Shodan ® - All rights reserved