|
222471
|
7.5 |
HIGH
Network
|
terra-master
|
fs-210_firmware
|
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= substring.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-18385
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222472
|
6.5 |
MEDIUM
Network
|
terra-master
|
fs-210_firmware
|
An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read unauthorized shared files, as demonstrated by the filename=*public*%25252Fadmin_…
|
NVD-CWE-noinfo
|
CVE-2019-18384
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222473
|
7.5 |
HIGH
Network
|
terra-master
|
fs-210_firmware
|
An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TNAS-00E43A_config_backup.bin without permission.
|
CWE-862
Missing Authorization
|
CVE-2019-18383
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222474
|
7.5 |
HIGH
Network
|
avstar
|
pe204_firmware
|
An issue was discovered on AVStar PE204 3.10.70 IP camera devices. A denial of service can occur on open TCP port 23456. After a TELNET connection, no TCP ports are open.
|
NVD-CWE-noinfo
|
CVE-2019-18382
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222475
|
7.5 |
HIGH
Network
|
mi
|
millet_router_3g_firmware
|
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files via a misconfigured NGINX alias, as demonstrated by a…
|
CWE-22
Path Traversal
|
CVE-2019-18371
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222476
|
5.5 |
MEDIUM
Local
|
glensawyer
|
mp3gain
|
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18359
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222477
|
9.8 |
CRITICAL
Network
|
mi
|
millet_router_3g_firmware
|
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can c…
|
CWE-78
OS Command
|
CVE-2019-18370
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222478
|
6.1 |
MEDIUM
Network
|
thycotic
|
secret_server
|
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-18357
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222479
|
6.1 |
MEDIUM
Network
|
thycotic
|
secret_server
|
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-18356
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222480
|
9.8 |
CRITICAL
Network
|
thycotic
|
secret_server
|
An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-18355
|
2024-11-21 13:33 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|