|
223091
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13954
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
7.8 |
HIGH
Local
|
gnu debian
|
patch debian_linux
|
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed edit…
|
CWE-78
OS Command
|
CVE-2019-13638
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
7.5 |
HIGH
Network
|
openldap canonical debian opensuse f5 apple oracle
|
openldap ubuntu_linux debian_linux leap traffix_signaling_delivery_controller mac_os_x solaris zfs_storage_appliance_kit blockchain_platform
|
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtai…
|
NVD-CWE-noinfo
|
CVE-2019-13565
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
9.8 |
CRITICAL
Network
|
exim debian
|
exim debian_linux
|
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $lo…
|
CWE-19
Data Processing Errors
|
CVE-2019-13917
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
7.2 |
HIGH
Network
|
ajdg
|
adrotate
|
The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-13570
|
2024-11-21 13:25 |
2019-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
9.8 |
CRITICAL
Network
|
icegram
|
email_subscribers_\&_newsletters
|
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to …
|
CWE-89
SQL Injection
|
CVE-2019-13569
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
6.5 |
MEDIUM
Adjacent
|
arduino
|
arduino_firmware
|
Embedded systems based on Arduino before Rev3 allow remote attackers to send data to LEDs (directly connected to GPIO pins) via a laser, because of LED photosensitivity.
|
NVD-CWE-noinfo
|
CVE-2019-13991
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
7.8 |
HIGH
Local
|
dpic_project
|
dpic
|
dpic 2019.06.20 has a Stack-based Buffer Overflow in the wfloat() function in main.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13989
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
8.8 |
HIGH
Network
|
rangerstudio
|
directus_7_api
|
Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demo…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-13984
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
9.8 |
CRITICAL
Network
|
rangerstudio
|
directus_7_api
|
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13983
|
2024-11-21 13:25 |
2019-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|