|
224221
|
8.8 |
HIGH
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
|
CWE-352
Origin Validation Error
|
CVE-2019-13563
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224222
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_s…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13562
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224223
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
|
CWE-78
OS Command
|
CVE-2019-13561
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224224
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
|
CWE-255
Credentials Management
|
CVE-2019-13560
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224225
|
9.8 |
CRITICAL
Network
|
hidea
|
az_admin
|
hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-13507
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224226
|
6.1 |
MEDIUM
Network
|
nuxtjs
|
\@nuxt\/devalue nuxt.js
|
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13506
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224227
|
6.1 |
MEDIUM
Network
|
dwbooster
|
appointment_hour_booking
|
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13505
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224228
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13504
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224229
|
7.5 |
HIGH
Network
|
cesanta
|
mongoose
|
mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13503
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224230
|
9.8 |
CRITICAL
Network
|
trape_project
|
trape
|
Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.
|
CWE-89
SQL Injection
|
CVE-2019-13489
|
2024-11-21 13:25 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|