|
212871
|
9.8 |
CRITICAL
Network
|
mobatek
|
mobaxterm
|
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from…
|
CWE-255
Credentials Management
|
CVE-2019-7690
|
2024-11-21 13:48 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212872
|
5.4 |
MEDIUM
Network
|
mythemeshop
|
launcher
|
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Ti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7411
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212873
|
6.1 |
MEDIUM
Network
|
vegadesign
|
profiledesign_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7409
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212874
|
7.5 |
HIGH
Network
|
lg
|
gamp-7100_firmware gapm-7200_firmware gapm-8000_firmware
|
An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request containing its full pathname, such as http://192.168.0.1/var…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7404
|
2024-11-21 13:48 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212875
|
7.7 |
HIGH
Network
|
thehive-project
|
cortex-analyzers
|
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an attacker must create a new analysis, select URL for Data Type…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-7652
|
2024-11-21 13:48 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212876
|
9.8 |
CRITICAL
Network
|
cyberark
|
enterprise_password_vault
|
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass a…
|
CWE-611
XXE
|
CVE-2019-7442
|
2024-11-21 13:48 |
2019-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212877
|
8.1 |
HIGH
Network
|
jio
|
jmr1140_firmware
|
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value ca…
|
CWE-352
Origin Validation Error
|
CVE-2019-7746
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212878
|
9.8 |
CRITICAL
Network
|
jio
|
jmr1140_firmware
|
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key f…
|
NVD-CWE-noinfo
|
CVE-2019-7745
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212879
|
6.1 |
MEDIUM
Network
|
jio
|
jmr1140_firmware
|
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7687
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212880
|
9.8 |
CRITICAL
Network
|
coship
|
rt3052_firmware rt3050_firmware wm3300_firmware rt7620_firmware
|
An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST requ…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7564
|
2024-11-21 13:48 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|