|
222971
|
7.3 |
HIGH
Local
|
webtoffee
|
import_export_wordpress_users
|
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported C…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-15092
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222972
|
9.8 |
CRITICAL
Network
|
cesnet
|
proxystatistics
|
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
|
CWE-89
SQL Injection
|
CVE-2019-15537
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222973
|
9.8 |
CRITICAL
Network
|
youracclaim
|
acclaim
|
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
|
CWE-89
SQL Injection
|
CVE-2019-15536
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222974
|
9.8 |
CRITICAL
Network
|
hostosm
|
tasking_manager
|
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
|
CWE-89
SQL Injection
|
CVE-2019-15535
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222975
|
6.5 |
MEDIUM
Network
|
gnu debian fedoraproject
|
libextractor debian_linux fedora
|
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15531
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222976
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field…
|
CWE-78
OS Command
|
CVE-2019-15530
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222977
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to L…
|
CWE-78
OS Command
|
CVE-2019-15529
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222978
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to …
|
CWE-78
OS Command
|
CVE-2019-15528
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222979
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to …
|
CWE-78
OS Command
|
CVE-2019-15527
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222980
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWa…
|
CWE-78
OS Command
|
CVE-2019-15526
|
2024-11-21 13:28 |
2019-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|