|
222991
|
9.8 |
CRITICAL
Network
|
givewp
|
givewp
|
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQ…
|
CWE-89
SQL Injection
|
CVE-2019-13578
|
2024-11-21 13:25 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222992
|
9.8 |
CRITICAL
Network
|
adenion
|
blog2social
|
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-13572
|
2024-11-21 13:25 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222993
|
8.8 |
HIGH
Network
|
cimg
|
cimg
|
CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13568
|
2024-11-21 13:25 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222994
|
9.1 |
CRITICAL
Network
|
wpfastestcache
|
wp_fastest_cache
|
The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-13635
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222995
|
6.5 |
MEDIUM
Network
|
imgix
|
imgix
|
Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-13655
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222996
|
9.8 |
CRITICAL
Network
|
vsourz
|
advanced_cf7_db
|
A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute a…
|
CWE-89
SQL Injection
|
CVE-2019-13571
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222997
|
7.4 |
HIGH
Network
|
oneidentity
|
cloud_access_manager
|
One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-13498
|
2024-11-21 13:25 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222998
|
6.1 |
MEDIUM
Network
|
wikindx_project
|
wikindx
|
A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via the PagingStart para…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13588
|
2024-11-21 13:25 |
2019-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222999
|
9.8 |
CRITICAL
Network
|
softwareag oracle apache netapp atlassian
|
quartz flexcube_investor_servicing retail_xstore_point_of_service flexcube_private_banking primavera_unifier retail_integration_bus retail_back_office webcenter_sites fusion_m…
|
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
|
CWE-611
XXE
|
CVE-2019-13990
|
2024-11-21 13:25 |
2019-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223000
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server via recursive…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13955
|
2024-11-21 13:25 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|