|
222361
|
9.8 |
CRITICAL
Network
|
netgate
|
pfsense
|
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_c…
|
CWE-22
Path Traversal
|
CVE-2019-16915
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222362
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense
|
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16914
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222363
|
9.8 |
CRITICAL
Network
|
inoideas
|
inoerp
|
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
|
CWE-89 CWE-502
SQL Injection Deserialization of Untrusted Data
|
CVE-2019-16894
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222364
|
7.5 |
HIGH
Network
|
netty debian canonical redhat
|
netty debian_linux ubuntu_linux jboss_enterprise_application_platform
|
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16869
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222365
|
9.8 |
CRITICAL
Network
|
bmc
|
myit_digital_workplace
|
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Opera…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16755
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222366
|
5.3 |
MEDIUM
Network
|
arm fedoraproject debian
|
mbed_crypto mbed_tls fedora debian_linux
|
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private…
|
NVD-CWE-noinfo
|
CVE-2019-16910
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222367
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the ch…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16904
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222368
|
5.3 |
MEDIUM
Network
|
plutinosoft
|
platinum
|
Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.
|
CWE-22
Path Traversal
|
CVE-2019-16903
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222369
|
5.3 |
MEDIUM
Network
|
mediawiki fedoraproject debian
|
mediawiki fedora debian_linux
|
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
|
CWE-862
Missing Authorization
|
CVE-2019-16738
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222370
|
7.5 |
HIGH
Network
|
advantech
|
webaccess\/hmi_designer
|
Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-16901
|
2024-11-21 13:31 |
2019-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|