|
223201
|
7.5 |
HIGH
Network
|
androvideo geovision
|
vd_1_firmware gv-vr360_firmware gv-vd8700_firmware
|
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without a…
|
CWE-22 CWE-862
Path Traversal Missing Authorization
|
CVE-2019-13408
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223202
|
6.1 |
MEDIUM
Network
|
androvideo geovision
|
vd_1_firmware gv-vr360_firmware gv-vd8700_firmware
|
A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the erro…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13407
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223203
|
7.5 |
HIGH
Network
|
androvideo
|
vd_1_firmware
|
A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without any authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13406
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223204
|
9.8 |
CRITICAL
Network
|
androvideo
|
vd_1_firmware
|
A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enable ADB without any au…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13405
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223205
|
8.8 |
HIGH
Network
|
eng
|
knowage
|
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-13348
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223206
|
6.1 |
MEDIUM
Network
|
eng
|
knowage
|
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13189
|
2024-11-21 13:24 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223207
|
8.8 |
HIGH
Adjacent
|
edimax
|
br-6208ac_v1_firmware
|
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network …
|
CWE-20
Improper Input Validation
|
CVE-2019-13270
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223208
|
8.8 |
HIGH
Adjacent
|
edimax
|
br-6208ac_v1_firmware
|
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a cert…
|
CWE-20
Improper Input Validation
|
CVE-2019-13269
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223209
|
8.8 |
HIGH
Adjacent
|
tp-link
|
archer_c3200_v1_firmware archer_c2_v1_firmware
|
TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, …
|
CWE-20
Improper Input Validation
|
CVE-2019-13268
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223210
|
9.8 |
CRITICAL
Network
|
xymon debian
|
xymon debian_linux
|
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13486
|
2024-11-21 13:24 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|