|
223631
|
9.8 |
CRITICAL
Network
|
hostosm
|
tasking_manager
|
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
|
CWE-89
SQL Injection
|
CVE-2019-15535
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223632
|
6.5 |
MEDIUM
Network
|
gnu debian fedoraproject
|
libextractor debian_linux fedora
|
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15531
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223633
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field…
|
CWE-78
OS Command
|
CVE-2019-15530
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223634
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to L…
|
CWE-78
OS Command
|
CVE-2019-15529
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223635
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to …
|
CWE-78
OS Command
|
CVE-2019-15528
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223636
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to …
|
CWE-78
OS Command
|
CVE-2019-15527
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223637
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWa…
|
CWE-78
OS Command
|
CVE-2019-15526
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223638
|
8.1 |
HIGH
Network
|
pw3270_project
|
pw3270
|
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15525
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223639
|
5.3 |
MEDIUM
Network
|
comelz
|
quark
|
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
|
CWE-22
Path Traversal
|
CVE-2019-15520
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223640
|
9.8 |
CRITICAL
Network
|
power-response_project
|
power-response
|
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
|
CWE-22
Path Traversal
|
CVE-2019-15519
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|