|
224441
|
8.8 |
HIGH
Network
|
cyberpowersystems
|
powerpanel
|
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an…
|
CWE-352
Origin Validation Error
|
CVE-2019-13071
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224442
|
9.8 |
CRITICAL
Network
|
oniguruma_project php fedoraproject debian canonical
|
oniguruma php fedora debian_linux ubuntu_linux
|
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted…
|
CWE-416
Use After Free
|
CVE-2019-13224
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224443
|
9.8 |
CRITICAL
Network
|
yoast
|
yoast_seo
|
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13478
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224444
|
8.8 |
HIGH
Network
|
mobatek
|
mobaxterm
|
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially crafted URL. Based on…
|
CWE-88
Argument Injection
|
CVE-2019-13475
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224445
|
6.1 |
MEDIUM
Network
|
phpwind
|
phpwind
|
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13472
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224446
|
9.8 |
CRITICAL
Network
|
matrixssl
|
matrixssl
|
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13470
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224447
|
6.1 |
MEDIUM
Network
|
keynto
|
team_password_manager
|
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13380
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224448
|
7.5 |
HIGH
Network
|
trendnet
|
tew-827dru_firmware
|
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard functionality, giving this attacker the ability to change configuration values…
|
NVD-CWE-noinfo
|
CVE-2019-13277
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224449
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13338
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224450
|
7.5 |
HIGH
Network
|
weseek
|
growi
|
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is…
|
CWE-639 CWE-863
Authorization Bypass Through User-Controlled Key Incorrect Authorization
|
CVE-2019-13337
|
2024-11-21 13:24 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|