|
222661
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to …
|
CWE-78
OS Command
|
CVE-2019-15528
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222662
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to …
|
CWE-78
OS Command
|
CVE-2019-15527
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222663
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWa…
|
CWE-78
OS Command
|
CVE-2019-15526
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222664
|
8.1 |
HIGH
Network
|
pw3270_project
|
pw3270
|
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15525
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222665
|
5.3 |
MEDIUM
Network
|
comelz
|
quark
|
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
|
CWE-22
Path Traversal
|
CVE-2019-15520
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222666
|
9.8 |
CRITICAL
Network
|
power-response_project
|
power-response
|
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
|
CWE-22
Path Traversal
|
CVE-2019-15519
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222667
|
5.3 |
MEDIUM
Network
|
swoole
|
swoole
|
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
|
CWE-22
Path Traversal
|
CVE-2019-15518
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222668
|
5.5 |
MEDIUM
Local
|
jc21
|
nginx_proxy_manager
|
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-15517
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222669
|
7.5 |
HIGH
Network
|
cuberite
|
cuberite
|
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
|
CWE-22
Path Traversal
|
CVE-2019-15516
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222670
|
5.3 |
MEDIUM
Network
|
telegram
|
telegram
|
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Grou…
|
NVD-CWE-noinfo
|
CVE-2019-15514
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|