|
212621
|
7.8 |
HIGH
Local
|
dahuasecurity
|
ipc-hfw1xxx_firmware ipc-hdw1xxx_firmware ipc-hfw2xxx_firmware
|
Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9676
|
2024-11-21 13:52 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212622
|
5.3 |
MEDIUM
Network
|
wpengine
|
wpgraphql
|
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9881
|
2024-11-21 13:52 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212623
|
9.1 |
CRITICAL
Network
|
wpengine
|
wpgraphql
|
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such a…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9880
|
2024-11-21 13:52 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212624
|
9.8 |
CRITICAL
Network
|
wpengine
|
wpgraphql
|
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutatio…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9879
|
2024-11-21 13:52 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212625
|
8.8 |
HIGH
Network
|
northern
|
cfengine
|
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-9929
|
2024-11-21 13:52 |
2019-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212626
|
9.8 |
CRITICAL
Network
|
pydio
|
pydio
|
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php fi…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9642
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212627
|
8.8 |
HIGH
Local
|
synaptics
|
sound_device
|
Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an un…
|
NVD-CWE-noinfo
|
CVE-2019-9730
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212628
|
8.8 |
HIGH
Network
|
freenetproject
|
freenet
|
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
|
CWE-19
Data Processing Errors
|
CVE-2019-9673
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212629
|
6.1 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.9.1 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9647
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212630
|
7.0 |
HIGH
Local
|
tuxera redhat
|
ntfs-3g enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to …
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-9755
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|