|
223081
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
|
CWE-255
Credentials Management
|
CVE-2019-13560
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223082
|
9.8 |
CRITICAL
Network
|
hidea
|
az_admin
|
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-13507
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223083
|
6.1 |
MEDIUM
Network
|
nuxtjs
|
\@nuxt\/devalue nuxt.js
|
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13506
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223084
|
6.1 |
MEDIUM
Network
|
dwbooster
|
appointment_hour_booking
|
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13505
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223085
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13504
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223086
|
7.5 |
HIGH
Network
|
cesanta
|
mongoose
|
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13503
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223087
|
9.8 |
CRITICAL
Network
|
trape_project
|
trape
|
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
|
CWE-89
SQL Injection
|
CVE-2019-13489
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223088
|
6.1 |
MEDIUM
Network
|
trape_project
|
trape
|
A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to inject arbitrary web script or HTML via the country, query, or refer parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2019-13488
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223089
|
3.3 |
LOW
Local
|
cisofy debian fedoraproject
|
lynis debian_linux fedora
|
In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis ser…
|
CWE-200
Information Exposure
|
CVE-2019-13033
|
2024-11-21 13:24 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223090
|
6.5 |
MEDIUM
Network
|
jetstream
|
jetselect
|
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users us…
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2019-13023
|
2024-11-21 13:24 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|