|
222851
|
7.5 |
HIGH
Network
|
asus
|
hg100_firmware mw100_firmware ws-101_firmware ts-101_firmware as-101_firmware ms-101_firmware dl-101_firmware
|
An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of ser…
|
CWE-20
Improper Input Validation
|
CVE-2019-15910
|
2024-11-21 13:29 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222852
|
7.5 |
HIGH
Network
|
http_server_project
|
http_server
|
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
|
CWE-22
Path Traversal
|
CVE-2019-15600
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222853
|
9.8 |
CRITICAL
Network
|
tree-kill_project
|
tree-kill
|
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
|
CWE-94
Code Injection
|
CVE-2019-15599
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222854
|
9.8 |
CRITICAL
Network
|
treekill_project
|
treekill
|
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
|
CWE-78
OS Command
|
CVE-2019-15598
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222855
|
9.8 |
CRITICAL
Network
|
node-df_project
|
node-df
|
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
|
CWE-94
Code Injection
|
CVE-2019-15597
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222856
|
7.5 |
HIGH
Network
|
statics-server_project
|
statics-server
|
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
|
CWE-22
Path Traversal
|
CVE-2019-15596
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222857
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipel…
|
NVD-CWE-Other
|
CVE-2019-15591
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222858
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token befor…
|
NVD-CWE-Other
|
CVE-2019-15589
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222859
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head…
|
CWE-200
Information Exposure
|
CVE-2019-15580
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222860
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-15577
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|