CVE-2019-16000 to CVE-2019-16999
185 CVEs with public proof-of-concept exploits.
- CVE-2019-160573 PoCsKEVThe login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
- CVE-2019-160611 PoCA number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions,…
- CVE-2019-160621 PoCNETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to…
- CVE-2019-160641 PoCNETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files…
- CVE-2019-160652 PoCsA remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to…
- CVE-2019-160661 PoCAn unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 and prior. This…
- CVE-2019-160671 PoCNETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of…
- CVE-2019-160682 PoCsA CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into…
- CVE-2019-160691 PoCA number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a…
- CVE-2019-160701 PoCA number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that could allow a…
- CVE-2019-160711 PoCEnigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any…
- CVE-2019-160723 PoCsAn OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to…
- CVE-2019-160881 PoCXpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.
- CVE-2019-160961 PoCKilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.
- CVE-2019-160978 PoCscore/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is…
- CVE-2019-160984 PoCsThe driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write…
- CVE-2019-161121 PoCTylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java object to the…
- CVE-2019-1611318 PoCsBludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and…
- CVE-2019-161162 PoCsEnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an…
- CVE-2019-161171 PoCCross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via…
- CVE-2019-161181 PoCCross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via…
- CVE-2019-161191 PoCSQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the…
- CVE-2019-161201 PoCCSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees"…
- CVE-2019-161232 PoCsIn Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
- CVE-2019-161241 PoCIn YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the…
- CVE-2019-161251 PoCIn Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injection.
- CVE-2019-161301 PoCYII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
- CVE-2019-161611 PoCOnigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.
- CVE-2019-161621 PoCOnigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.
- CVE-2019-161631 PoCOniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
- CVE-2019-161641 PoCMyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.
- CVE-2019-161671 PoCsysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
- CVE-2019-161725 PoCsLimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The…
- CVE-2019-161734 PoCsLimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This…
- CVE-2019-161972 PoCsIn htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text…
- CVE-2019-161981 PoCKSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
- CVE-2019-162131 PoCTenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By…
- CVE-2019-162141 PoCLibra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere…
- CVE-2019-162171 PoCWordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
- CVE-2019-162181 PoCWordPress before 5.2.3 allows XSS in stored comments.
- CVE-2019-162191 PoCWordPress before 5.2.3 allows XSS in shortcode previews.
- CVE-2019-162201 PoCIn WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open…
- CVE-2019-162211 PoCWordPress before 5.2.3 allows reflected XSS in the dashboard.
- CVE-2019-162221 PoCWordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site…
- CVE-2019-162233 PoCsWordPress before 5.2.3 allows XSS in post previews by authenticated users.
- CVE-2019-162241 PoCAn issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy destination,…
- CVE-2019-162251 PoCAn issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_pg[mc->top],…
- CVE-2019-162261 PoCAn issue was discovered in py-lmdb 0.97. mdb_node_del does not validate a memmove in the case of an unexpected node->mn_hi, leading to an…
- CVE-2019-162271 PoCAn issue was discovered in py-lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invalid write operation…
- CVE-2019-162281 PoCAn issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a…
- CVE-2019-162461 PoCIntesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated…
- CVE-2019-162471 PoCDelta DCISoft 1.21 has a User Mode Write AV starting at CommLib!CCommLib::SetSerializeData+0x000000000000001b.
- CVE-2019-162481 PoCThe "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In…
- CVE-2019-162501 PoCincludes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a…
- CVE-2019-162531 PoCThe Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacker to escalate…
- CVE-2019-162641 PoCIn Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the…
- CVE-2019-162681 PoCZoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration…
- CVE-2019-1627834 PoCsKEVDirectory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a…
- CVE-2019-162792 PoCsA memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted…
- CVE-2019-162821 PoCIn NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An…
- CVE-2019-162891 PoCThe insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.
- CVE-2019-162942 PoCsSciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a…
- CVE-2019-162951 PoCStored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be…
- CVE-2019-163032 PoCsA class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an insecure source…
- CVE-2019-163071 PoCA Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji…
- CVE-2019-163133 PoCsifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
- CVE-2019-163261 PoCD-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction…
- CVE-2019-163271 PoCD-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely…
- CVE-2019-163301 PoCIn NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes…
- CVE-2019-163322 PoCsIn the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php…
- CVE-2019-163361 PoCThe Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames with a payload…
- CVE-2019-163371 PoCThe hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
- CVE-2019-163381 PoCThe tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
- CVE-2019-163401 PoCBelkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the…
- CVE-2019-163461 PoCngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small…
- CVE-2019-163481 PoCmarc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
- CVE-2019-163491 PoCBento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom…
- CVE-2019-163501 PoCffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
- CVE-2019-163511 PoCffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
- CVE-2019-163521 PoCffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
- CVE-2019-163701 PoCThe PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a…
- CVE-2019-163831 PoCMOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an…
- CVE-2019-163841 PoCCybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the…
- CVE-2019-163851 PoCCybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as…
- CVE-2019-163941 PoCSPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail…
- CVE-2019-163991 PoCWestern Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/…
- CVE-2019-164041 PoCAuthenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data…
- CVE-2019-164053 PoCsCentreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an…
- CVE-2019-164143 PoCsA DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's…
- CVE-2019-164161 PoCHRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
- CVE-2019-164171 PoCHRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
- CVE-2019-164511 PoCAdobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version,…
- CVE-2019-164691 PoCAdobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful…
- CVE-2019-165122 PoCsAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance…
- CVE-2019-165132 PoCsAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
- CVE-2019-165142 PoCsAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution.…
- CVE-2019-165151 PoCAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not…
- CVE-2019-165164 PoCsAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumeration…
- CVE-2019-165172 PoCsAn issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which…
- CVE-2019-165202 PoCsThe all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding…
- CVE-2019-165212 PoCsThe broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper…
- CVE-2019-165221 PoCThe eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of…
- CVE-2019-165232 PoCsThe events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and…
- CVE-2019-165242 PoCsThe easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu…
- CVE-2019-165252 PoCsAn XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filtered in the…
- CVE-2019-165312 PoCsLayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
- CVE-2019-165322 PoCsAn HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
- CVE-2019-166381 PoCAn issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with…
- CVE-2019-166391 PoCAn issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an…
- CVE-2019-166411 PoCAn issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use…
- CVE-2019-166421 PoCApp\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
- CVE-2019-166441 PoCApp\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
- CVE-2019-166452 PoCsAn issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links…
- CVE-2019-166511 PoCAn issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient…
- CVE-2019-166626 PoCsAn issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to…
- CVE-2019-166636 PoCsAn issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php…
- CVE-2019-166672 PoCsdiag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.…
- CVE-2019-166781 PoCadmin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
- CVE-2019-166791 PoCGila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
- CVE-2019-166801 PoCAn issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR…
- CVE-2019-166922 PoCsphpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
- CVE-2019-166931 PoCphpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
- CVE-2019-167012 PoCspfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing…
- CVE-2019-167022 PoCsIntegard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the…
- CVE-2019-167051 PoCMing (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in libutil.a.
- CVE-2019-167162 PoCsOX App Suite through 7.10.2 has Incorrect Access Control.
- CVE-2019-167172 PoCsOX App Suite through 7.10.2 has XSS.
- CVE-2019-167245 PoCsFile Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH)…
- CVE-2019-167281 PoCDOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome…
- CVE-2019-167291 PoCpam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root…
- CVE-2019-167301 PoCprocessCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute…
- CVE-2019-167311 PoCThe udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate firmware upgrades…
- CVE-2019-167321 PoCUnencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as…
- CVE-2019-167331 PoCprocessCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute…
- CVE-2019-167341 PoCUse of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to…
- CVE-2019-167351 PoCA stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30…
- CVE-2019-167361 PoCA stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30…
- CVE-2019-167371 PoCThe processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to…
- CVE-2019-167461 PoCAn issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in…
- CVE-2019-167541 PoCRIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a…
- CVE-2019-167582 PoCsIn Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using…
- CVE-2019-1675930 PoCsKEVvBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring…
- CVE-2019-167631 PoCXSS in Pannellum from 2.5.0 through 2.5.4
- CVE-2019-167691 PoCAffected versions of serialize-javascript are vulnerable to Cross-site Scripting (XSS)
- CVE-2019-167801 PoCStored cross-site scripting (XSS) in WordPress block editor
- CVE-2019-167811 PoCStored cross-site scripting (XSS) in WordPress block editor
- CVE-2019-167842 PoCsLocal Privilege Escalation present only on the Windows version of PyInstaller
- CVE-2019-168641 PoCCompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user…
- CVE-2019-168681 PoCemlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory…
- CVE-2019-168691 PoCNetty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which…
- CVE-2019-168841 PoCrunc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because…
- CVE-2019-168852 PoCsIn OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted…
- CVE-2019-168892 PoCsUbiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in…
- CVE-2019-168913 PoCsLiferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
- CVE-2019-168921 PoCIn Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can…
- CVE-2019-168932 PoCsThe Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a…
- CVE-2019-168941 PoCdownload.php in inoERP 4.15 allows SQL injection through insecure deserialization.
- CVE-2019-168971 PoCIn K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Security 16.0.xxx…
- CVE-2019-169022 PoCsIn the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by…
- CVE-2019-169071 PoCAn issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obtain a list of all…
- CVE-2019-169081 PoCAn issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list…
- CVE-2019-169091 PoCAn issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list…
- CVE-2019-169131 PoCPC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user…
- CVE-2019-169171 PoCWiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the…
- CVE-2019-169204 PoCsKEVUnauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when…
- CVE-2019-169312 PoCsA stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript…
- CVE-2019-169321 PoCA blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
- CVE-2019-169351 PoCThe documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field.…
- CVE-2019-169411 PoCNSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns…
- CVE-2019-169481 PoCAn SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at…
- CVE-2019-169491 PoCAn issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their chat log to an email…
- CVE-2019-169501 PoCAn XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion…
- CVE-2019-169511 PoCA remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own…
- CVE-2019-169541 PoCSolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
- CVE-2019-169551 PoCSolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
- CVE-2019-169561 PoCSolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
- CVE-2019-169571 PoCSolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
- CVE-2019-169581 PoCCross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via…
- CVE-2019-169591 PoCSolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
- CVE-2019-169601 PoCSolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
- CVE-2019-169611 PoCSolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
- CVE-2019-169621 PoCZoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
- CVE-2019-169963 PoCsIn Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the…
- CVE-2019-169973 PoCsIn Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the…
- CVE-2019-169991 PoCCloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.