|
223811
|
6.1 |
MEDIUM
Network
|
squid-cache debian
|
squid debian_linux
|
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13345
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223812
|
5.3 |
MEDIUM
Network
|
crudlab
|
wp_like_button
|
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13344
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223813
|
4.8 |
MEDIUM
Network
|
1234n
|
minicms
|
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13341
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223814
|
4.8 |
MEDIUM
Network
|
1234n
|
minicms
|
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13340
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223815
|
4.8 |
MEDIUM
Network
|
1234n
|
minicms
|
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13339
|
2024-11-21 13:24 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223816
|
7.8 |
HIGH
Local
|
redhat
|
virt-bootstrap
|
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
|
CWE-200
Information Exposure
|
CVE-2019-13314
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223817
|
7.8 |
HIGH
Local
|
libosinfo fedoraproject redhat
|
libosinfo fedora enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
|
CWE-200
Information Exposure
|
CVE-2019-13313
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223818
|
9.8 |
CRITICAL
Network
|
mytinytodo
|
mytinytodo
|
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-13144
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223819
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-13312
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223820
|
6.5 |
MEDIUM
Network
|
imagemagick canonical debian opensuse
|
imagemagick ubuntu_linux debian_linux leap
|
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-13311
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|