|
222691
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr840n_firmware
|
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
|
CWE-78
OS Command
|
CVE-2019-15060
|
2024-11-21 13:27 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222692
|
7.5 |
HIGH
Network
|
nltk
|
nltk
|
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during e…
|
CWE-22
Path Traversal
|
CVE-2019-14751
|
2024-11-21 13:27 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222693
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus_\+_security_2019 internet_security_2019 maximum_security_2019 premium_security_2019 ransom_buster
|
A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14686
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222694
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus_\+_security_2019 internet_security_2019 maximum_security_2019 premium_security_2019
|
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious ser…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-14685
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222695
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
|
CWE-200
Information Exposure
|
CVE-2019-15045
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222696
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14687
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222697
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14684
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222698
|
7.5 |
HIGH
Network
|
vanderbilt
|
redcap
|
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a …
|
CWE-89
SQL Injection
|
CVE-2019-14937
|
2024-11-21 13:27 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222699
|
8.8 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
|
CWE-78
OS Command
|
CVE-2019-14923
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222700
|
6.1 |
MEDIUM
Network
|
kunalnagar
|
custom_404_pro
|
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14789
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|