|
222511
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
|
CWE-200
Information Exposure
|
CVE-2019-15045
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222512
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14687
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222513
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14684
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222514
|
7.5 |
HIGH
Network
|
vanderbilt
|
redcap
|
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a …
|
CWE-89
SQL Injection
|
CVE-2019-14937
|
2024-11-21 13:27 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222515
|
8.8 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
|
CWE-78
OS Command
|
CVE-2019-14923
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222516
|
6.1 |
MEDIUM
Network
|
kunalnagar
|
custom_404_pro
|
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14789
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222517
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the s…
|
CWE-22
Path Traversal
|
CVE-2019-14788
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222518
|
6.5 |
MEDIUM
Network
|
rankmath
|
seo
|
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
|
CWE-862
Missing Authorization
|
CVE-2019-14786
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222519
|
6.1 |
MEDIUM
Network
|
codepeople
|
cp_contact_form_with_paypal
|
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14784
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222520
|
5.3 |
MEDIUM
Network
|
foliovision
|
fv_flowplayer_video_player
|
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1…
|
CWE-200
Information Exposure
|
CVE-2019-14800
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|