|
223421
|
8.8 |
HIGH
Network
|
xpertsol
|
server_status_by_hostname\/ip
|
A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.
|
CWE-89
SQL Injection
|
CVE-2019-12570
|
2024-11-21 13:23 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223422
|
9.8 |
CRITICAL
Network
|
dosbox debian
|
dosbox debian_linux
|
DOSBox 0.74-2 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-12594
|
2024-11-21 13:23 |
2019-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223423
|
8.8 |
HIGH
Network
|
wpchef
|
widget_logic
|
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that ar…
|
CWE-352
Origin Validation Error
|
CVE-2019-12826
|
2024-11-21 13:23 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223424
|
5.3 |
MEDIUM
Network
|
djangoproject canonical debian
|
django ubuntu_linux debian_linux
|
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT set…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-12781
|
2024-11-21 13:23 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223425
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious…
|
CWE-79
Cross-site Scripting
|
CVE-2019-12970
|
2024-11-21 13:23 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223426
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete search form placed in the header of out/out.Viewfolder.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12932
|
2024-11-21 13:23 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223427
|
8.8 |
HIGH
Network
|
icon
|
loopchain
|
In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAULT_SCORE_HOST environment variable).
|
CWE-78
OS Command
|
CVE-2019-12997
|
2024-11-21 13:23 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223428
|
7.5 |
HIGH
Network
|
istio
|
istio
|
Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is related to a jwt_authenticator.cc segmentation fault.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-12995
|
2024-11-21 13:23 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223429
|
6.1 |
MEDIUM
Network
|
zyxel
|
uag2100_firmware uag4100_firmware uag5100_firmware usg110_firmware usg210_firmware usg310_firmware usg1100_firmware usg1900_firmware usg2200-vpn_firmware
|
A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, USG, and UAG devices allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2019-12581
|
2024-11-21 13:23 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223430
|
8.1 |
HIGH
Network
|
keyidentity
|
linotp
|
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2019-12887
|
2024-11-21 13:23 |
2019-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|