|
222171
|
4.8 |
MEDIUM
Network
|
dlink
|
dir-615_firmware
|
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19742
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222172
|
7.5 |
HIGH
Network
|
sqlite netapp debian suse redhat opensuse oracle siemens
|
sqlite cloud_backup debian_linux package_hub enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap backports_sle mysql_workbench sinec_infra…
|
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19880
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222173
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
|
CWE-89
SQL Injection
|
CVE-2019-19846
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222174
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
|
CWE-22
Path Traversal
|
CVE-2019-19845
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222175
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.
|
CWE-601
Open Redirect
|
CVE-2019-19775
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222176
|
9.8 |
CRITICAL
Network
|
verot_project getk2
|
verot k2
|
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a sim…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-19634
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222177
|
7.2 |
HIGH
Network
|
typo3
|
typo3
|
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL inje…
|
CWE-89
SQL Injection
|
CVE-2019-19850
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222178
|
7.2 |
HIGH
Network
|
typo3
|
typo3
|
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnera…
|
CWE-22
Path Traversal
|
CVE-2019-19848
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222179
|
8.1 |
HIGH
Network
|
libspiro_project
|
libspiro
|
Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19847
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222180
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserializat…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19849
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|