|
222521
|
4.8 |
MEDIUM
Network
|
toggle-the-title_project
|
toggle-the-title
|
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parame…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14795
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222522
|
6.1 |
MEDIUM
Network
|
limbcode
|
limb-gallery
|
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
|
CWE-79
Cross-site Scripting
|
CVE-2019-14790
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222523
|
8.8 |
HIGH
Network
|
leaftecnologia
|
leaf_admin
|
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14755
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222524
|
8.0 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could…
|
CWE-352
Origin Validation Error
|
CVE-2019-15062
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222525
|
9.1 |
CRITICAL
Network
|
stb_project
|
stb
|
stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15058
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222526
|
9.8 |
CRITICAL
Network
|
gradle
|
gradle
|
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subs…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-15052
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222527
|
6.8 |
MEDIUM
Network
|
atlassian
|
html_include_and_replace_macro
|
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15053
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222528
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15050
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222529
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15049
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222530
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15048
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|