|
222371
|
6.1 |
MEDIUM
Network
|
yofla
|
360_product_rotation
|
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15082
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222372
|
7.8 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability …
|
CWE-416
Use After Free
|
CVE-2019-15239
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222373
|
6.1 |
MEDIUM
Network
|
getflightpath
|
flightpath
|
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15227
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222374
|
7.4 |
HIGH
Network
|
roundcube fedoraproject
|
webmail fedora
|
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
|
NVD-CWE-noinfo
|
CVE-2019-15237
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222375
|
9.8 |
CRITICAL
Network
|
live555
|
streaming_media
|
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and …
|
CWE-416
Use After Free
|
CVE-2019-15232
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222376
|
8.8 |
HIGH
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially craft…
|
CWE-352
Origin Validation Error
|
CVE-2019-15229
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222377
|
5.4 |
MEDIUM
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated acc…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15228
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222378
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to r…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15225
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222379
|
9.8 |
CRITICAL
Network
|
rest-client_project
|
rest-client
|
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
|
CWE-94
Code Injection
|
CVE-2019-15224
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222380
|
4.6 |
MEDIUM
Physics
|
linux netapp canonical
|
linux_kernel h410c_firmware data_availability_services solidfire_\&_hci_management_node active_iq_unified_manager solidfire_baseboard_management_controller ubuntu_linux
|
An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15223
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|