|
212761
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8425
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212762
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8424
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212763
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8423
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212764
|
7.2 |
HIGH
Network
|
pbootcms
|
pbootcms
|
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.
|
CWE-89
SQL Injection
|
CVE-2019-8422
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212765
|
7.2 |
HIGH
Network
|
bagesoft
|
bagecms
|
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8421
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212766
|
6.1 |
MEDIUM
Network
|
vnote_project
|
vnote
|
VNote 2.2 has XSS via a new text note.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8419
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212767
|
8.8 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS 7.2 mishandles member.php?mod=repsw4 requests.
|
NVD-CWE-noinfo
|
CVE-2019-8418
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212768
|
5.5 |
MEDIUM
Local
|
mi
|
mi_mix_2_firmware
|
On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8413
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212769
|
8.8 |
HIGH
Network
|
feifeicms
|
feifeicms
|
FeiFeiCms 4.0.181010 on Windows allows remote attackers to read or delete arbitrary files via index.php?s=Admin-Data-Down-id-..\ or index.php?s=Admin-Data-Del-id-..\ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-8412
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212770
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-8411
|
2024-11-21 13:49 |
2019-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|