|
223241
|
6.1 |
MEDIUM
Network
|
kkcms_project
|
kkcms
|
kkcms 1.3 has jx.php?url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16923
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223242
|
5.3 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
|
NVD-CWE-noinfo
|
CVE-2019-16922
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223243
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive info…
|
CWE-665
Improper Initialization
|
CVE-2019-16921
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223244
|
7.5 |
HIGH
Network
|
reputeinfosystems
|
arforms
|
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
|
CWE-22
Path Traversal
|
CVE-2019-16902
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223245
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware dir-866l_firmware dir-652_firmware dhp-1565_firmware dir-855l_firmware dap-1533_firmware dir-862l_firmware dir-615_firmware dir-835_firmware dir-825_firmwa…
|
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device c…
|
CWE-78
OS Command
|
CVE-2019-16920
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223246
|
9.8 |
CRITICAL
Network
|
netgate
|
pfsense
|
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_c…
|
CWE-22
Path Traversal
|
CVE-2019-16915
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223247
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense
|
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16914
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223248
|
9.8 |
CRITICAL
Network
|
inoideas
|
inoerp
|
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
|
CWE-89 CWE-502
SQL Injection Deserialization of Untrusted Data
|
CVE-2019-16894
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223249
|
7.5 |
HIGH
Network
|
netty debian canonical redhat
|
netty debian_linux ubuntu_linux jboss_enterprise_application_platform
|
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16869
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223250
|
9.8 |
CRITICAL
Network
|
bmc
|
myit_digital_workplace
|
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Opera…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16755
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|