|
225731
|
7.5 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" process. By sending a specially crafted UDP packet, an attacker could exploit t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-19506
|
2024-11-21 13:34 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225732
|
8.8 |
HIGH
Network
|
tendacn
|
pa6_firmware
|
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the "Wireless" section in the web-UI. By sending a specially crafted …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19505
|
2024-11-21 13:34 |
2020-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225733
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19112
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225734
|
6.1 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19111
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225735
|
4.8 |
MEDIUM
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19110
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225736
|
8.8 |
HIGH
Network
|
gvectors
|
wpforo
|
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-19109
|
2024-11-21 13:34 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225737
|
4.6 |
MEDIUM
Physics
|
huawei
|
alp-al00b_firmware alp-l09_firmware alp-l29_firmware anne-al00_firmware bla-al00b_firmware bla-l09c_firmware bla-l29c_firmware berkeley-al20_firmware berkeley-l09_firmware …
|
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the …
|
NVD-CWE-noinfo
|
CVE-2019-19412
|
2024-11-21 13:34 |
2020-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225738
|
6.1 |
MEDIUM
Network
|
wowza
|
streaming_engine
|
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19456
|
2024-11-21 13:34 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225739
|
7.5 |
HIGH
Network
|
wowza
|
streaming_engine
|
An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
|
NVD-CWE-noinfo
|
CVE-2019-19454
|
2024-11-21 13:34 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225740
|
7.8 |
HIGH
Local
|
tobesoft
|
xplatform
|
A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system running it.
|
CWE-416
Use After Free
|
CVE-2019-19162
|
2024-11-21 13:34 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|