|
222201
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16223
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222202
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16222
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222203
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows reflected XSS in the dashboard.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16221
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222204
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forwar…
|
CWE-601
Open Redirect
|
CVE-2019-16220
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222205
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in shortcode previews.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16219
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222206
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in stored comments.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16218
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222207
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16217
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222208
|
5.4 |
MEDIUM
Network
|
esri
|
arcgis_enterprise
|
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16193
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222209
|
5.7 |
MEDIUM
Network
|
libra
|
libra_core
|
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character f…
|
NVD-CWE-noinfo
|
CVE-2019-16214
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222210
|
7.5 |
HIGH
Network
|
humanica
|
humatrix
|
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16106
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|