|
211271
|
7.5 |
HIGH
Network
|
yubico
|
libu2f-host
|
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-9578
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211272
|
5.3 |
MEDIUM
Network
|
sagemcom
|
f\@st_5260_firmware
|
Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The numbe…
|
CWE-331
Insufficient Entropy
|
CVE-2019-9555
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211273
|
5.5 |
MEDIUM
Local
|
linux debian redhat opensuse canonical
|
linux_kernel debian_linux enterprise_linux leap ubuntu_linux
|
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SM…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9213
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211274
|
6.1 |
MEDIUM
Network
|
adenion
|
blog2social
|
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9576
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211275
|
6.1 |
MEDIUM
Network
|
quizandsurveymaster
|
quiz_and_survey_master
|
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9575
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211276
|
7.5 |
HIGH
Network
|
mishubd
|
wp_human_resource_management
|
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.
|
CWE-862
Missing Authorization
|
CVE-2019-9574
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211277
|
7.5 |
HIGH
Network
|
mishubd
|
wp_human_resource_management
|
The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications.
|
CWE-19
Data Processing Errors
|
CVE-2019-9573
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211278
|
7.2 |
HIGH
Network
|
schoolcms
|
schoolcms
|
SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9572
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211279
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9570
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211280
|
6.5 |
MEDIUM
Network
|
incsub
|
forminator
|
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delet…
|
CWE-89
SQL Injection
|
CVE-2019-9568
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|