|
222741
|
6.5 |
MEDIUM
Adjacent
|
yalehome
|
yale_bluetooth_key
|
The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energy (BLE) traffic during one authorized unlock action, and then calculating the a…
|
CWE-287
Improper Authentication
|
CVE-2019-17627
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222742
|
9.8 |
CRITICAL
Network
|
reportlab
|
reportlab
|
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
|
CWE-91
Blind XPath Injection
|
CVE-2019-17626
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222743
|
9.0 |
CRITICAL
Network
|
rambox
|
rambox
|
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field …
|
CWE-79 CWE-78
Cross-site Scripting OS Command
|
CVE-2019-17625
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222744
|
7.8 |
HIGH
Local
|
x.org
|
x_server
|
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sending ct.c_char 1000 times, an attacker can cause a denial of service (application …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17624
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222745
|
9.8 |
CRITICAL
Network
|
qibosoft
|
qibosoft
|
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attac…
|
CWE-94
Code Injection
|
CVE-2019-17613
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222746
|
7.2 |
HIGH
Network
|
74cms
|
74cms
|
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sor…
|
CWE-89
SQL Injection
|
CVE-2019-17612
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222747
|
9.8 |
CRITICAL
Network
|
rapidgator
|
rapidgator
|
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-17395
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222748
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability coul…
|
CWE-89
SQL Injection
|
CVE-2019-17602
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222749
|
9.8 |
CRITICAL
Network
|
minishare_project
|
minishare
|
In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17601
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222750
|
9.8 |
CRITICAL
Network
|
darkhorse
|
dark_horse_comics
|
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-17398
|
2024-11-21 13:32 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|