|
222561
|
9.8 |
CRITICAL
Network
|
westerndigital
|
wd_my_book_firmware
|
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials. An attacker can easily enable SSH…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16399
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222562
|
8.8 |
HIGH
Network
|
webkul
|
bagisto
|
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-16403
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222563
|
5.4 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting atta…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16216
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222564
|
6.5 |
MEDIUM
Network
|
zulip
|
zulip_server
|
The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2019-16215
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222565
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code.
|
CWE-416
Use After Free
|
CVE-2019-16396
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222566
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16395
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222567
|
5.3 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscr…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16394
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222568
|
6.1 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
|
CWE-601
Open Redirect
|
CVE-2019-16393
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222569
|
6.1 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16392
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222570
|
6.5 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrir…
|
NVD-CWE-noinfo
|
CVE-2019-16391
|
2024-11-21 13:30 |
2019-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|