|
222751
|
7.5 |
HIGH
Network
|
gcdwebserver_project
|
gcdwebserver
|
An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerabi…
|
CWE-863
Incorrect Authorization
|
CVE-2019-14924
|
2024-11-21 13:27 |
2019-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222752
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mobilefrontend
|
In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14807
|
2024-11-21 13:27 |
2019-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222753
|
7.5 |
HIGH
Network
|
palletsprojects opensuse
|
werkzeug leap
|
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
|
CWE-331
Insufficient Entropy
|
CVE-2019-14806
|
2024-11-21 13:27 |
2019-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222754
|
4.8 |
MEDIUM
Network
|
una
|
una
|
studio/builder_menu.php?page=sets in UNA 10.0.0-RC1 allows XSS via the System Name field under Sets during set editing.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14805
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222755
|
4.8 |
MEDIUM
Network
|
una
|
una
|
studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14804
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222756
|
9.8 |
CRITICAL
Network
|
foliovision
|
fv_flowplayer_video_player
|
The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-14801
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222757
|
4.9 |
MEDIUM
Network
|
10web
|
photo_gallery
|
The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the wp-admin/admin-ajax.php?action=shortcode_bwg tagtext parameter.
|
CWE-22
Path Traversal
|
CVE-2019-14798
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222758
|
5.4 |
MEDIUM
Network
|
10web
|
photo_gallery
|
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14797
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222759
|
5.4 |
MEDIUM
Network
|
mq-woocommerce-products-price-bulk-edit_project
|
mq-woocommerce-products-price-bulk-edit
|
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=update_options show_products_page_lim…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14796
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222760
|
7.5 |
HIGH
Network
|
metabox
|
meta_box
|
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
|
CWE-19
Data Processing Errors
|
CVE-2019-14794
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|