|
219291
|
7.5 |
HIGH
Network
|
advance_peer_to_peer_mlm_script_project
|
advance_peer_to_peer_mlm_script
|
The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.p…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-6126
|
2024-11-21 13:45 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219292
|
9.8 |
CRITICAL
Network
|
nelson-it
|
open_source_erp
|
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
|
CWE-89
SQL Injection
|
CVE-2019-5893
|
2024-11-21 13:45 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219293
|
6.5 |
MEDIUM
Network
|
frrouting
|
frrouting
|
bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x before 6.0.2 (not affecting Cumulus Linux or VyOS), when ENABLE_BGP_VNC is used fo…
|
CWE-436
Interpretation Conflict
|
CVE-2019-5892
|
2024-11-21 13:45 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219294
|
7.5 |
HIGH
Network
|
shopxo
|
shopxo
|
An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input mishandling by the rmdir method. Attackers can dele…
|
CWE-22
Path Traversal
|
CVE-2019-5887
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219295
|
9.8 |
CRITICAL
Network
|
shopxo
|
shopxo
|
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. …
|
CWE-667 CWE-862
Improper Locking Missing Authorization
|
CVE-2019-5886
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219296
|
5.9 |
MEDIUM
Network
|
std42
|
elfinder
|
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
|
CWE-200
Information Exposure
|
CVE-2019-5884
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219297
|
9.8 |
CRITICAL
Network
|
irssi canonical
|
irssi ubuntu_linux
|
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
|
CWE-416
Use After Free
|
CVE-2019-5882
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219298
|
9.8 |
CRITICAL
Network
|
traccar
|
server
|
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
|
CWE-611
XXE
|
CVE-2019-5748
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219299
|
7.5 |
HIGH
Network
|
busybox canonical
|
busybox ubuntu_linux
|
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive inform…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5747
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219300
|
7.5 |
HIGH
Network
|
qibosoft
|
qibosoft
|
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql file.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-5725
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|