|
223151
|
7.5 |
HIGH
Network
|
hinet
|
gpon_firmware
|
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0…
|
NVD-CWE-noinfo
|
CVE-2019-13412
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223152
|
7.5 |
HIGH
Network
|
topmeeting
|
topmeeting
|
TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacker to obtain sensitive information by browsing the source code of the page.
|
CWE-200
Information Exposure
|
CVE-2019-13410
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223153
|
9.8 |
CRITICAL
Network
|
topmeeting
|
topmeeting
|
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databa…
|
CWE-89
SQL Injection
|
CVE-2019-13409
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223154
|
9.8 |
CRITICAL
Network
|
hinet
|
gpon_firmware
|
An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execute arbitrary command through port 3097. CVSS 3.0 Base score 10.0. CVSS vector: …
|
NVD-CWE-noinfo
|
CVE-2019-13411
|
2024-11-21 13:24 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223155
|
9.8 |
CRITICAL
Network
|
mulesoft
|
mule_runtime
|
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-13116
|
2024-11-21 13:24 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223156
|
6.1 |
MEDIUM
Network
|
mindpalette
|
natemail
|
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The app…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13392
|
2024-11-21 13:24 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223157
|
8.8 |
HIGH
Network
|
pi-hole
|
pi-hole
|
Pi-Hole 4.3 allows Command Injection.
|
CWE-78
OS Command
|
CVE-2019-13051
|
2024-11-21 13:24 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223158
|
9.8 |
CRITICAL
Network
|
dbell
|
db01-s_firmware
|
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to open…
|
CWE-287
Improper Authentication
|
CVE-2019-13336
|
2024-11-21 13:24 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223159
|
7.5 |
HIGH
Network
|
amazon
|
amazon_web_services_freertos
|
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacke…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13120
|
2024-11-21 13:24 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223160
|
7.8 |
HIGH
Local
|
foxitsoftware
|
reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the targ…
|
CWE-416
Use After Free
|
CVE-2019-13320
|
2024-11-21 13:24 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|