|
223511
|
4.3 |
MEDIUM
Adjacent
|
vandyvape
|
swell_kit_mod_firmware
|
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Ener…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2019-16518
|
2024-11-21 13:30 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223512
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
|
CWE-89
SQL Injection
|
CVE-2019-16695
|
2024-11-21 13:30 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223513
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used.
|
CWE-89
SQL Injection
|
CVE-2019-16694
|
2024-11-21 13:30 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223514
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
|
CWE-89
SQL Injection
|
CVE-2019-16693
|
2024-11-21 13:30 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223515
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
|
CWE-89
SQL Injection
|
CVE-2019-16692
|
2024-11-21 13:30 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223516
|
4.7 |
MEDIUM
Network
|
traveloka
|
traveloka
|
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16681
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223517
|
4.3 |
MEDIUM
Network
|
gnome redhat debian canonical
|
file-roller enterprise_linux debian_linux ubuntu_linux
|
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
|
CWE-22
Path Traversal
|
CVE-2019-16680
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223518
|
4.9 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
|
CWE-22
Path Traversal
|
CVE-2019-16679
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223519
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
|
CWE-352
Origin Validation Error
|
CVE-2019-16678
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223520
|
6.5 |
MEDIUM
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-16677
|
2024-11-21 13:30 |
2019-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|