|
222771
|
4.3 |
MEDIUM
Network
|
acf\
|
_better_search_project
|
The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-14682
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222772
|
8.8 |
HIGH
Network
|
deny_all_firewall_project
|
deny_all_firewall
|
The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-14681
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222773
|
5.7 |
MEDIUM
Network
|
mijnpress
|
admin-renamer-extended
|
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-14680
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222774
|
6.5 |
MEDIUM
Network
|
reputeinfosystems
|
arprice_lite
|
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-14679
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222775
|
8.1 |
HIGH
Network
|
zohocorp
|
manageengine_assetexplorer
|
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sen…
|
CWE-611
XXE
|
CVE-2019-14693
|
2024-11-21 13:27 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222776
|
6.1 |
MEDIUM
Network
|
verdaccio
|
verdaccio
|
verdaccio before 3.12.0 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14772
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222777
|
9.8 |
CRITICAL
Network
|
open-school
|
open-school
|
Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-14754
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222778
|
6.1 |
MEDIUM
Network
|
backdropcms
|
backdrop_core
|
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the sear…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14770
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222779
|
6.1 |
MEDIUM
Network
|
backdropcms
|
backdrop
|
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a spe…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14769
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222780
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock with f_hid.
|
CWE-667
Improper Locking
|
CVE-2019-14763
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|