|
223031
|
9.8 |
CRITICAL
Network
|
dlink
|
central_wifimanager
|
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username fi…
|
CWE-287 CWE-94
Improper Authentication Code Injection
|
CVE-2019-13372
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223032
|
8.8 |
HIGH
Network
|
ignitedcms
|
ignitedcms
|
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
|
CWE-352
Origin Validation Error
|
CVE-2019-13370
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223033
|
7.8 |
HIGH
Local
|
codedoc_project
|
codedoc
|
Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13362
|
2024-11-21 13:24 |
2019-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223034
|
7.5 |
HIGH
Network
|
opencats
|
opencats
|
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.
|
CWE-611
XXE
|
CVE-2019-13358
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223035
|
9.8 |
CRITICAL
Network
|
wolfvision
|
cynap
|
WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorit…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13352
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223036
|
8.1 |
HIGH
Network
|
jackaudio alsa-project
|
jack2 alsa
|
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jac…
|
NVD-CWE-noinfo
|
CVE-2019-13351
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223037
|
6.1 |
MEDIUM
Network
|
squid-cache debian
|
squid debian_linux
|
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13345
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223038
|
5.3 |
MEDIUM
Network
|
crudlab
|
wp_like_button
|
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13344
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223039
|
4.8 |
MEDIUM
Network
|
1234n
|
minicms
|
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13341
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223040
|
4.8 |
MEDIUM
Network
|
1234n
|
minicms
|
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13340
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|