|
222701
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the s…
|
CWE-22
Path Traversal
|
CVE-2019-14788
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222702
|
6.5 |
MEDIUM
Network
|
rankmath
|
seo
|
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
|
CWE-862
Missing Authorization
|
CVE-2019-14786
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222703
|
6.1 |
MEDIUM
Network
|
codepeople
|
cp_contact_form_with_paypal
|
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14784
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222704
|
5.3 |
MEDIUM
Network
|
foliovision
|
fv_flowplayer_video_player
|
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1…
|
CWE-200
Information Exposure
|
CVE-2019-14800
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222705
|
4.8 |
MEDIUM
Network
|
toggle-the-title_project
|
toggle-the-title
|
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parame…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14795
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222706
|
6.1 |
MEDIUM
Network
|
limbcode
|
limb-gallery
|
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
|
CWE-79
Cross-site Scripting
|
CVE-2019-14790
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222707
|
8.8 |
HIGH
Network
|
leaftecnologia
|
leaf_admin
|
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14755
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222708
|
8.0 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could…
|
CWE-352
Origin Validation Error
|
CVE-2019-15062
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222709
|
9.1 |
CRITICAL
Network
|
stb_project
|
stb
|
stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15058
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222710
|
9.8 |
CRITICAL
Network
|
gradle
|
gradle
|
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subs…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-15052
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|