|
221911
|
7.5 |
HIGH
Network
|
dlink
|
dir-816_a1_firmware
|
An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top.location.href = "/dir_login.asp"' line in a .asp …
|
CWE-20
Improper Input Validation
|
CVE-2019-17507
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221912
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-868l_b1_firmware dir-817lw_a1_firmware
|
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other informati…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17506
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221913
|
7.5 |
HIGH
Network
|
dlink
|
dap-1320_a2_firmware
|
D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, wh…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17505
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221914
|
6.1 |
MEDIUM
Network
|
kirona
|
dynamic_resource_scheduling
|
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/r…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17504
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221915
|
9.8 |
CRITICAL
Network
|
fasterxml debian redhat oracle netapp
|
jackson-databind debian_linux jboss_enterprise_application_platform banking_platform jd_edwards_enterpriseone_tools primavera_gateway weblogic_server webcenter_portal webcente…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17531
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221916
|
7.5 |
HIGH
Network
|
python
|
python
|
library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether sorting occurs, as demonstrated by irreproducible cancer-research results. NOTE:…
|
NVD-CWE-noinfo CWE-682
Incorrect Calculation
|
CVE-2019-17514
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221917
|
5.3 |
MEDIUM
Network
|
kirona
|
dynamic_resource_scheduling
|
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive informa…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-17503
|
2024-11-21 13:32 |
2019-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221918
|
8.8 |
HIGH
Network
|
compal
|
ch7465lg_firmware
|
The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execut…
|
CWE-78
OS Command
|
CVE-2019-17499
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221919
|
6.5 |
MEDIUM
Network
|
tracker-software
|
pdf-xchange_editor
|
Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link t…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-17497
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221920
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17496
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|