|
222171
|
8.8 |
HIGH
Network
|
mobatek
|
mobaxterm
|
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted,…
|
CWE-77
Command Injection
|
CVE-2019-16305
|
2024-11-21 13:30 |
2019-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222172
|
9.8 |
CRITICAL
Network
|
jhipster
|
jhipster jhipster_kotlin
|
A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source of randomness (apache.commons.lang3 RandomStringUtils). This a…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2019-16303
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222173
|
8.8 |
HIGH
Network
|
opmantek
|
open-audit
|
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
|
CWE-78
OS Command
|
CVE-2019-16293
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222174
|
5.4 |
MEDIUM
Network
|
webcraftic
|
woody_ad_snippets
|
The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16289
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222175
|
7.5 |
HIGH
Network
|
tenda
|
n301_firmware
|
On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash.
|
NVD-CWE-noinfo
|
CVE-2019-16288
|
2024-11-21 13:30 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222176
|
7.8 |
HIGH
Local
|
picoc_project
|
picoc
|
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16277
|
2024-11-21 13:30 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222177
|
6.5 |
MEDIUM
Adjacent
|
w1.fi debian canonical
|
hostapd wpa_supplicant debian_linux ubuntu_linux
|
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service th…
|
CWE-346
Origin Validation Error
|
CVE-2019-16275
|
2024-11-21 13:30 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222178
|
6.1 |
MEDIUM
Network
|
afterlogic
|
aurora
|
Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16238
|
2024-11-21 13:30 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222179
|
9.1 |
CRITICAL
Network
|
tripplite
|
pdumh15at_firmware
|
Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NO…
|
CWE-287
Improper Authentication
|
CVE-2019-16261
|
2024-11-21 13:30 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222180
|
9.8 |
CRITICAL
Network
|
motorola
|
motorola_firmware
|
Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or ex…
|
NVD-CWE-noinfo
|
CVE-2019-16257
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|