|
223461
|
7.2 |
HIGH
Network
|
hp
|
260_g1_dm_firmware 280_pro_g1_firmware 285_g2_firmware 340_g3_firmware 340_g4_firmware 346_g3_firmware 346_g4_firmware 348_g3_firmware 348_g4_firmware elite_slice_firmware<…
|
A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of pr…
|
NVD-CWE-noinfo
|
CVE-2019-16284
|
2024-11-21 13:30 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223462
|
7.8 |
HIGH
Local
|
phoenixcontact
|
pc_worx_express config\+ pc_worx
|
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds R…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16675
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223463
|
4.6 |
MEDIUM
Local
|
control-webpanel
|
webpanel
|
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16295
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223464
|
4.3 |
MEDIUM
Network
|
yithemes
|
yith_woocommerce_wishlist yith_woocommerce_compare yith_woocommerce_quick_view yith_woocommerce_zoom_magnifier yith_woocommerce_ajax_search yith_woocommerce_badge_management yith_wo…
|
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
|
NVD-CWE-noinfo
|
CVE-2019-16251
|
2024-11-21 13:30 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223465
|
7.2 |
HIGH
Network
|
maxthon
|
maxthon_browser
|
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-16647
|
2024-11-21 13:30 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223466
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function …
|
CWE-78
OS Command
|
CVE-2019-16663
|
2024-11-21 13:30 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223467
|
9.8 |
CRITICAL
Network
|
rconfig
|
rconfig
|
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec …
|
CWE-78
OS Command
|
CVE-2019-16662
|
2024-11-21 13:30 |
2019-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223468
|
9.8 |
CRITICAL
Network
|
codesys
|
eni_server codesys
|
CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16265
|
2024-11-21 13:30 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223469
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO s…
|
CWE-89
SQL Injection
|
CVE-2019-16404
|
2024-11-21 13:30 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223470
|
7.2 |
HIGH
Network
|
sonatype
|
nexus_repository_manager nexus_iq_server
|
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16530
|
2024-11-21 13:30 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|