|
225781
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-859_firmware dir-822_firmware dir-823_firmware dir-865l_firmware dir-868l_firmware dir-869_firmware dir-880l_firmware dir-890l_firmware dir-890r_firmware dir-885l_firmw…
|
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted…
|
CWE-78
OS Command
|
CVE-2019-17621
|
2024-11-21 13:32 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225782
|
6.1 |
MEDIUM
Network
|
reliablecontrols
|
mach-prowebsys_firmware mach-prowebcom_firmware
|
Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commands on behalf of the user when an authenticated user clicks on…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18249
|
2024-11-21 13:32 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225783
|
8.8 |
HIGH
Network
|
orckestra
|
c1_cms
|
An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to unvalidated deserialization of wrapped BinaryFormatter payloads, leading to arbit…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18211
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225784
|
7.8 |
HIGH
Local
|
we-con
|
plc_editor
|
Multiple buffer overflow vulnerabilities exist when the PLC Editor Version 1.3.5_20190129 processes project files. An attacker could use a specially crafted project file to exploit and execute code u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-18236
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225785
|
9.8 |
CRITICAL
Network
|
equinoxce
|
control_expert
|
Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2019-18234
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225786
|
7.5 |
HIGH
Network
|
apache debian opensuse canonical oracle
|
tomcat debian_linux leap ubuntu_linux transportation_management retail_order_broker micros_relate_crm_software instantis_enterprisetrack hyperion_infrastructure_technology …
|
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The wind…
|
CWE-384
Session Fixation
|
CVE-2019-17563
|
2024-11-21 13:32 |
2019-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225787
|
9.8 |
CRITICAL
Network
|
apache debian canonical opensuse netapp oracle
|
log4j debian_linux ubuntu_linux leap oncommand_workflow_automation oncommand_system_manager retail_service_backbone weblogic_server application_testing_suite endeca_informa…
|
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization ga…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17571
|
2024-11-21 13:32 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225788
|
6.5 |
MEDIUM
Adjacent
|
philips
|
veradius_unity_firmware pulsera_firmware endura_firmware
|
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewFo…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-18263
|
2024-11-21 13:32 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225789
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC …
|
NVD-CWE-Other
|
CVE-2019-17440
|
2024-11-21 13:32 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225790
|
9.8 |
CRITICAL
Network
|
joomsky
|
js_jobs
|
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfiel…
|
CWE-89
SQL Injection
|
CVE-2019-17527
|
2024-11-21 13:32 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|