|
210931
|
5.3 |
MEDIUM
Adjacent
|
ushareit
|
shareit
|
The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-9938
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210932
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9937
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210933
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is relate…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9936
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210934
|
9.8 |
CRITICAL
Network
|
caret
|
caret
|
Caret before 2019-02-22 allows Remote Code Execution.
|
NVD-CWE-noinfo
|
CVE-2019-9927
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210935
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9925
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210936
|
7.8 |
HIGH
Local
|
gnu debian opensuse netapp canonical
|
bash debian_linux leap solidfire hci_management_node ubuntu_linux
|
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
|
CWE-862
Missing Authorization
|
CVE-2019-9924
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210937
|
7.5 |
HIGH
Network
|
gnu opensuse
|
tar leap
|
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9923
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210938
|
6.1 |
MEDIUM
Network
|
get-simple.
|
getsimplecms
|
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
|
CWE-601
Open Redirect
|
CVE-2019-9915
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210939
|
6.1 |
MEDIUM
Network
|
yop-poll
|
yop-poll
|
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9914
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210940
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9913
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|