|
213311
|
9.8 |
CRITICAL
Network
|
phpmyadmin
|
phpmyadmin
|
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
|
CWE-89
SQL Injection
|
CVE-2019-6798
|
2024-11-21 13:47 |
2019-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213312
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1-628. The AP4_ElstAtom class in Core/Ap4ElstAtom.cpp has an attempted excessive memory allocation related to AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6966
|
2024-11-21 13:47 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213313
|
7.1 |
HIGH
Local
|
audiocoding debian
|
freeware_advanced_audio_decoder_2 debian_linux
|
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6956
|
2024-11-21 13:47 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213314
|
9.8 |
CRITICAL
Network
|
s-cms
|
s-cms
|
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6805
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213315
|
6.1 |
MEDIUM
Network
|
pagerduty
|
rundeck
|
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6804
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213316
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6803
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213317
|
6.1 |
MEDIUM
Network
|
python
|
pypiserver
|
CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS attacks via a %0d%0a in a URI.
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2019-6802
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213318
|
6.1 |
MEDIUM
Network
|
kaine
|
wise_chat
|
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.
|
CWE-601
Open Redirect
|
CVE-2019-6780
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213319
|
8.1 |
HIGH
Network
|
chshcms
|
cscms
|
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.
|
CWE-352
Origin Validation Error
|
CVE-2019-6779
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213320
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6777
|
2024-11-21 13:47 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|