|
222731
|
6.5 |
MEDIUM
Network
|
imagemagick opensuse
|
imagemagick leap
|
In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafte…
|
CWE-416
Use After Free
|
CVE-2019-14980
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222732
|
6.1 |
MEDIUM
Network
|
icmsdev
|
icms
|
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14976
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222733
|
9.8 |
CRITICAL
Network
|
txjia
|
imcat
|
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
|
CWE-89
SQL Injection
|
CVE-2019-14968
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222734
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14967
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222735
|
7.8 |
HIGH
Local
|
netwrix
|
auditor
|
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to t…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14969
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222736
|
8.8 |
HIGH
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-14966
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222737
|
9.8 |
CRITICAL
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
|
CWE-94
Code Injection
|
CVE-2019-14965
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222738
|
7.5 |
HIGH
Network
|
telenav
|
scout_gps_link
|
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it eas…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-14951
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222739
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14947
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222740
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14946
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|