|
222281
|
8.8 |
HIGH
Network
|
netgate
|
pfsense
|
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
|
CWE-78
OS Command
|
CVE-2019-16701
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222282
|
9.8 |
CRITICAL
Network
|
emlog
|
emlog
|
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
|
CWE-22
Path Traversal
|
CVE-2019-16868
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222283
|
6.5 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and…
|
CWE-22
Path Traversal
|
CVE-2019-16867
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222284
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
|
CWE-94
Code Injection
|
CVE-2019-16759
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222285
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16725
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222286
|
9.8 |
CRITICAL
Network
|
upredsun
|
file_sharing_wizard
|
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar iss…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16724
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222287
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16754
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222288
|
6.1 |
MEDIUM
Network
|
devise_token_auth_project
|
devise_token_auth
|
An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16751
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222289
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in Chec…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16748
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222290
|
9.8 |
CRITICAL
Network
|
linux debian canonical fedoraproject opensuse
|
linux_kernel debian_linux ubuntu_linux fedora leap
|
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16746
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|