|
223301
|
8.8 |
HIGH
Network
|
mobatek
|
mobaxterm
|
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially crafted URL. Based on…
|
CWE-88
Argument Injection
|
CVE-2019-13475
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223302
|
6.1 |
MEDIUM
Network
|
phpwind
|
phpwind
|
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13472
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223303
|
9.8 |
CRITICAL
Network
|
matrixssl
|
matrixssl
|
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13470
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223304
|
6.1 |
MEDIUM
Network
|
keynto
|
team_password_manager
|
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13380
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223305
|
7.5 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard functionality, giving this attacker the ability to change configuration values…
|
NVD-CWE-noinfo
|
CVE-2019-13277
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223306
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13338
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223307
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is…
|
CWE-639 CWE-863
Authorization Bypass Through User-Controlled Key Incorrect Authorization
|
CVE-2019-13337
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223308
|
7.5 |
HIGH
Network
|
modsecurity
|
owasp_modsecurity_core_rule_set
|
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots int…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-13464
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223309
|
8.8 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an error message to the user about failure to resolve a hostname during a ping or …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13280
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223310
|
5.4 |
MEDIUM
Network
|
cyberpowersystems
|
powerpanel
|
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Up…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13070
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|