|
222551
|
6.1 |
MEDIUM
Network
|
draytek
|
vigor2925_firmware
|
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16534
|
2024-11-21 13:30 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222552
|
6.1 |
MEDIUM
Network
|
draytek
|
vigor2925_firmware
|
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16533
|
2024-11-21 13:30 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222553
|
9.8 |
CRITICAL
Network
|
yejiao
|
tuzicms
|
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
|
CWE-89
SQL Injection
|
CVE-2019-16642
|
2024-11-21 13:30 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222554
|
8.8 |
HIGH
Network
|
layerbb
|
layerbb
|
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-16531
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222555
|
6.1 |
MEDIUM
Network
|
checklist
|
checklist
|
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the checklist-icon.php file, and it is possible to inject JavaScript co…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16525
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222556
|
5.5 |
MEDIUM
Local
|
firegiant
|
wix_toolset
|
An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Microsoft.Deployment.Compression.Zip.dll allow directory traversal during CAB or ZI…
|
CWE-22
Path Traversal
|
CVE-2019-16511
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222557
|
7.5 |
HIGH
Network
|
mz-automation
|
libiec61850
|
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.
|
CWE-416
Use After Free
|
CVE-2019-16510
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222558
|
7.5 |
HIGH
Network
|
tendacn
|
n301_firmware
|
In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Prohibition of this zero value is only enforced within the GUI.)
|
CWE-20
Improper Input Validation
|
CVE-2019-16412
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222559
|
6.8 |
MEDIUM
Physics
|
keeper
|
k5_firmware
|
On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file named zskj_script_run.sh that executes a reverse shell.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-16398
|
2024-11-21 13:30 |
2019-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222560
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-16413
|
2024-11-21 13:30 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|