|
224161
|
9.8 |
CRITICAL
Network
|
dormsystem_project
|
dormsystem
|
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
|
CWE-89
SQL Injection
|
CVE-2019-17580
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224162
|
7.5 |
HIGH
Network
|
dlink
|
dir-412_firmware
|
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the i…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17511
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224163
|
6.1 |
MEDIUM
Network
|
sonarsource
|
sonarqube
|
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17579
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224164
|
7.2 |
HIGH
Network
|
wbce
|
wbce_cms
|
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extensi…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-17575
|
2024-11-21 13:32 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224165
|
9.1 |
CRITICAL
Network
|
code-atlantic
|
popup_maker
|
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-17574
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224166
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
|
CWE-89
SQL Injection
|
CVE-2019-17553
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224167
|
9.8 |
CRITICAL
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
|
CWE-89
SQL Injection
|
CVE-2019-17552
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224168
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
|
CWE-94
Code Injection
|
CVE-2019-17408
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224169
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free.
|
CWE-416
Use After Free
|
CVE-2019-17547
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224170
|
8.8 |
HIGH
Network
|
libtiff osgeo
|
libtiff gdal
|
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, rela…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-17546
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|