|
222821
|
9.8 |
CRITICAL
Network
|
indexhibit
|
indexhibit
|
Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
|
NVD-CWE-noinfo
|
CVE-2019-16314
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222822
|
7.5 |
HIGH
Network
|
ifw8
|
fr6_firmware fr8_firmware fr5_firmware fr5-e_firmware fr6-s_firmware
|
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-16313
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222823
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16312
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222824
|
8.8 |
HIGH
Network
|
niushop
|
niushop
|
NIUSHOP V1.11 has CSRF via search_info to index.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-16311
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222825
|
5.4 |
MEDIUM
Network
|
niushop
|
niushop
|
NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16310
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222826
|
9.8 |
CRITICAL
Network
|
flamecms_project
|
flamecms
|
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
|
CWE-89
SQL Injection
|
CVE-2019-16309
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222827
|
7.8 |
HIGH
Local
|
notepad-plus-plus scintilla
|
notepad\+\+ scintilla
|
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16294
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222828
|
8.8 |
HIGH
Network
|
mobatek
|
mobaxterm
|
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,…
|
CWE-77
Command Injection
|
CVE-2019-16305
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222829
|
9.8 |
CRITICAL
Network
|
jhipster
|
jhipster jhipster_kotlin
|
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2019-16303
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222830
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
|
CWE-78
OS Command
|
CVE-2019-16293
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|