|
223191
|
9.6 |
CRITICAL
Network
|
piwigo
|
piwigo
|
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-13363
|
2024-11-21 13:24 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223192
|
9.8 |
CRITICAL
Network
|
telestar auna
|
bobs_rock_radio_firmware dabman_d10_firmware dabman_i30_stereo_firmware imperial_i110_firmware imperial_i150_firmware imperial_i200_firmware imperial_i200-cd_firmware imperial_i4…
|
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13473
|
2024-11-21 13:24 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223193
|
4.9 |
MEDIUM
Network
|
knowage-suite
|
knowage
|
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-13349
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223194
|
7.5 |
HIGH
Network
|
mapsolutions
|
intramaps
|
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.
|
CWE-89
SQL Injection
|
CVE-2019-13191
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223195
|
9.8 |
CRITICAL
Network
|
eng
|
knowage
|
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
|
CWE-287
Improper Authentication
|
CVE-2019-13188
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223196
|
9.8 |
CRITICAL
Network
|
symphonyextensions
|
rich_text_formatter
|
The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-13187
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223197
|
6.5 |
MEDIUM
Adjacent
|
smanos
|
w100_firmware
|
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
|
CWE-287
Improper Authentication
|
CVE-2019-13361
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223198
|
5.3 |
MEDIUM
Network
|
eng
|
knowage
|
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
|
CWE-287
Improper Authentication
|
CVE-2019-13190
|
2024-11-21 13:24 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223199
|
6.1 |
MEDIUM
Network
|
suse
|
rancher
|
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13209
|
2024-11-21 13:24 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223200
|
7.5 |
HIGH
Network
|
naver
|
cloud_explorer
|
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13156
|
2024-11-21 13:24 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|