|
222651
|
6.1 |
MEDIUM
Network
|
status_board_project
|
status_board
|
Status Board 1.1.81 has reflected XSS via logic.ts.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15478
|
2024-11-21 13:28 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222652
|
7.8 |
HIGH
Local
|
cdemu
|
libmirage
|
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15540
|
2024-11-21 13:28 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222653
|
7.5 |
HIGH
Network
|
linux canonical netapp opensuse debian fedoraproject
|
linux_kernel ubuntu_linux data_availability_services solidfire hci_management_node aff_a700s_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_f…
|
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsi…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-15538
|
2024-11-21 13:28 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222654
|
7.3 |
HIGH
Local
|
webtoffee
|
import_export_wordpress_users
|
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported C…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-15092
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222655
|
9.8 |
CRITICAL
Network
|
cesnet
|
proxystatistics
|
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
|
CWE-89
SQL Injection
|
CVE-2019-15537
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222656
|
9.8 |
CRITICAL
Network
|
youracclaim
|
acclaim
|
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
|
CWE-89
SQL Injection
|
CVE-2019-15536
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222657
|
9.8 |
CRITICAL
Network
|
hostosm
|
tasking_manager
|
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
|
CWE-89
SQL Injection
|
CVE-2019-15535
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222658
|
6.5 |
MEDIUM
Network
|
gnu debian fedoraproject
|
libextractor debian_linux fedora
|
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15531
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222659
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field…
|
CWE-78
OS Command
|
CVE-2019-15530
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222660
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to L…
|
CWE-78
OS Command
|
CVE-2019-15529
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|