|
212631
|
8.8 |
HIGH
Network
|
beescms
|
beescms
|
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-8347
|
2024-11-21 13:49 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212632
|
4.2 |
MEDIUM
Adjacent
|
estrongs
|
es_file_explorer_file_manager
|
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-8345
|
2024-11-21 13:49 |
2019-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212633
|
7.8 |
HIGH
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
|
CWE-416
Use After Free
|
CVE-2019-8343
|
2024-11-21 13:49 |
2019-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212634
|
9.8 |
CRITICAL
Network
|
pocoo opensuse
|
jinja2 leap
|
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then ret…
|
CWE-94
Code Injection
|
CVE-2019-8341
|
2024-11-21 13:49 |
2019-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212635
|
5.3 |
MEDIUM
Network
|
marlam
|
msmtp mpop
|
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-8337
|
2024-11-21 13:49 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212636
|
6.1 |
MEDIUM
Network
|
schoolcms
|
schoolcms
|
An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&id=[XSS].
|
CWE-79
Cross-site Scripting
|
CVE-2019-8335
|
2024-11-21 13:49 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212637
|
6.1 |
MEDIUM
Network
|
schoolcms
|
schoolcms
|
An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&viewid=[XSS].
|
CWE-79
Cross-site Scripting
|
CVE-2019-8334
|
2024-11-21 13:49 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212638
|
8.8 |
HIGH
Network
|
dlink
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injecti…
|
CWE-78
OS Command
|
CVE-2019-8319
|
2024-11-21 13:49 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212639
|
8.8 |
HIGH
Network
|
dlink
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injecti…
|
CWE-78
OS Command
|
CVE-2019-8318
|
2024-11-21 13:49 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212640
|
8.8 |
HIGH
Network
|
dlink
|
dir-878_firmware
|
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injecti…
|
CWE-78
OS Command
|
CVE-2019-8317
|
2024-11-21 13:49 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|