|
223331
|
6.1 |
MEDIUM
Network
|
dlink
|
central_wifimanager
|
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13374
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223332
|
9.8 |
CRITICAL
Network
|
dlink
|
central_wifimanager
|
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Pub…
|
CWE-89
SQL Injection
|
CVE-2019-13373
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223333
|
9.8 |
CRITICAL
Network
|
dlink
|
central_wifimanager
|
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username fi…
|
CWE-287 CWE-94
Improper Authentication Code Injection
|
CVE-2019-13372
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223334
|
8.8 |
HIGH
Network
|
ignitedcms
|
ignitedcms
|
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
|
CWE-352
Origin Validation Error
|
CVE-2019-13370
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223335
|
7.8 |
HIGH
Local
|
codedoc_project
|
codedoc
|
Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13362
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223336
|
7.5 |
HIGH
Network
|
opencats
|
opencats
|
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
|
CWE-611
XXE
|
CVE-2019-13358
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223337
|
9.8 |
CRITICAL
Network
|
wolfvision
|
cynap
|
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorit…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13352
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223338
|
8.1 |
HIGH
Network
|
jackaudio alsa-project
|
jack2 alsa
|
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jac…
|
NVD-CWE-noinfo
|
CVE-2019-13351
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223339
|
6.1 |
MEDIUM
Network
|
squid-cache debian
|
squid debian_linux
|
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13345
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223340
|
5.3 |
MEDIUM
Network
|
crudlab
|
wp_like_button
|
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13344
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|