|
222301
|
9.8 |
CRITICAL
Network
|
cesnet
|
proxystatistics
|
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
|
CWE-89
SQL Injection
|
CVE-2019-15537
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222302
|
9.8 |
CRITICAL
Network
|
youracclaim
|
acclaim
|
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
|
CWE-89
SQL Injection
|
CVE-2019-15536
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222303
|
9.8 |
CRITICAL
Network
|
hostosm
|
tasking_manager
|
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
|
CWE-89
SQL Injection
|
CVE-2019-15535
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222304
|
6.5 |
MEDIUM
Network
|
gnu debian fedoraproject
|
libextractor debian_linux fedora
|
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15531
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222305
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field…
|
CWE-78
OS Command
|
CVE-2019-15530
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222306
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to L…
|
CWE-78
OS Command
|
CVE-2019-15529
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222307
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to …
|
CWE-78
OS Command
|
CVE-2019-15528
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222308
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to …
|
CWE-78
OS Command
|
CVE-2019-15527
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222309
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWa…
|
CWE-78
OS Command
|
CVE-2019-15526
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222310
|
8.1 |
HIGH
Network
|
pw3270_project
|
pw3270
|
There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-15525
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|