|
223411
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
|
CWE-89
SQL Injection
|
CVE-2019-12351
|
2024-11-21 13:22 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223412
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
|
CWE-89
SQL Injection
|
CVE-2019-12350
|
2024-11-21 13:22 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223413
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12349
|
2024-11-21 13:22 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223414
|
9.8 |
CRITICAL
Network
|
gok tecson
|
smartbox_4_lan_firmware smartbox_4_lan_pro_firmware lx-q-net_firmware lx-net_firmware e-litro_net_firmware
|
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user w…
|
-
|
CVE-2019-12254
|
2024-11-21 13:22 |
2022-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223415
|
9.8 |
CRITICAL
Network
|
wyze
|
cam_pan_v2_firmware cam_v2_firmware cam_v3_firmware
|
Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on the affected device. This issue affects: Wyze Cam Pan v2 versions prior to 4.4…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12266
|
2024-11-21 13:22 |
2022-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223416
|
6.5 |
MEDIUM
Local
|
qemu debian fedoraproject redhat
|
qemu debian_linux fedora enterprise_linux openstack_platform
|
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-12067
|
2024-11-21 13:22 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223417
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
|
CWE-89
SQL Injection
|
CVE-2019-12348
|
2024-11-21 13:22 |
2021-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223418
|
7.5 |
HIGH
Network
|
apache
|
libapreq2
|
A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-12412
|
2024-11-21 13:22 |
2020-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223419
|
6.5 |
MEDIUM
Adjacent
|
actions-micro
|
ezcast_pro_ii_firmware
|
In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access the administration panel of the device.
|
NVD-CWE-noinfo
|
CVE-2019-12305
|
2024-11-21 13:22 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223420
|
6.1 |
MEDIUM
Network
|
whatsapp
|
whatsapp_desktop
|
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.
|
CWE-79
Cross-site Scripting
|
CVE-2019-11928
|
2024-11-21 13:22 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|