|
222601
|
7.5 |
HIGH
Network
|
ifw8
|
fr6_firmware fr8_firmware fr5_firmware fr5-e_firmware fr6-s_firmware
|
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16313
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222602
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16312
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222603
|
8.8 |
HIGH
Network
|
niushop
|
niushop
|
NIUSHOP V1.11 has CSRF via search_info to index.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-16311
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222604
|
5.4 |
MEDIUM
Network
|
niushop
|
niushop
|
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16310
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222605
|
9.8 |
CRITICAL
Network
|
flamecms_project
|
flamecms
|
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
|
CWE-89
SQL Injection
|
CVE-2019-16309
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222606
|
7.8 |
HIGH
Local
|
notepad-plus-plus scintilla
|
notepad\+\+ scintilla
|
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16294
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222607
|
8.8 |
HIGH
Network
|
mobatek
|
mobaxterm
|
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,…
|
CWE-77
Command Injection
|
CVE-2019-16305
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222608
|
9.8 |
CRITICAL
Network
|
jhipster
|
jhipster jhipster_kotlin
|
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2019-16303
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222609
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
|
CWE-78
OS Command
|
CVE-2019-16293
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222610
|
5.4 |
MEDIUM
Network
|
webcraftic
|
woody_ad_snippets
|
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16289
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|