|
221721
|
8.8 |
HIGH
Network
|
cabsoftware
|
reportexpress_proplus
|
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-19160
|
2024-11-21 13:34 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221722
|
7.5 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-19506
|
2024-11-21 13:34 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221723
|
8.8 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19505
|
2024-11-21 13:34 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221724
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19112
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221725
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19111
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221726
|
4.8 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19110
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221727
|
8.8 |
HIGH
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-19109
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221728
|
4.6 |
MEDIUM
Physics
|
huawei
|
alp-al00b_firmware alp-l09_firmware alp-l29_firmware anne-al00_firmware bla-al00b_firmware bla-l09c_firmware bla-l29c_firmware berkeley-al20_firmware berkeley-l09_firmware …
|
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the …
|
NVD-CWE-noinfo
|
CVE-2019-19412
|
2024-11-21 13:34 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221729
|
6.1 |
MEDIUM
Network
|
wowza
|
streaming_engine
|
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19456
|
2024-11-21 13:34 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221730
|
7.5 |
HIGH
Network
|
wowza
|
streaming_engine
|
An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
|
NVD-CWE-noinfo
|
CVE-2019-19454
|
2024-11-21 13:34 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|