|
222331
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2875al_firmware dsl-2877al_firmware
|
D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_…
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2019-15656
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222332
|
7.5 |
HIGH
Network
|
dlink
|
dsl-2875al_firmware
|
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and …
|
CWE-306 CWE-522
Missing Authentication for Critical Function Insufficiently Protected Credentials
|
CVE-2019-15655
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222333
|
7.5 |
HIGH
Network
|
comba
|
ac2400_firmware
|
Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doesn't require any aut…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15654
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222334
|
7.5 |
HIGH
Network
|
comba
|
ap2600-i_-_a02_-_0202n00pd2_firmware
|
Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining th…
|
CWE-327 CWE-311 CWE-522
Use of a Broken or Risky Cryptographic Algorithm Missing Encryption of Sensitive Data Insufficiently Protected Credentials
|
CVE-2019-15653
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222335
|
8.1 |
HIGH
Network
|
cisco
|
sd-wan_firmware
|
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists …
|
CWE-89
SQL Injection
|
CVE-2019-16012
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222336
|
4.8 |
MEDIUM
Network
|
cisco
|
sd-wan_firmware
|
A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based managem…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16010
|
2024-11-21 13:29 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222337
|
6.7 |
MEDIUM
Local
|
fortinet
|
fortiap-w2 fortiap-s fortiap-u fortiap
|
A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administra…
|
CWE-78
OS Command
|
CVE-2019-15708
|
2024-11-21 13:29 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222338
|
5.9 |
MEDIUM
Network
|
yarnpkg
|
yarn
|
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. Th…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-15608
|
2024-11-21 13:29 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222339
|
9.8 |
CRITICAL
Network
|
kill-port-process_project
|
kill-port-process
|
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
|
CWE-78
OS Command
|
CVE-2019-15609
|
2024-11-21 13:29 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222340
|
3.3 |
LOW
Local
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r354735, and 11.3-RELEASE before 11.3-RELEASE-p6, due to incorrect…
|
CWE-665
Improper Initialization
|
CVE-2019-15875
|
2024-11-21 13:29 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|