|
222491
|
5.4 |
MEDIUM
Network
|
semperplugins
|
all_in_one_seo_pack
|
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plu…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16520
|
2024-11-21 13:30 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222492
|
5.4 |
MEDIUM
Network
|
nchsoftware
|
express_invoice
|
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Cu…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16282
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222493
|
7.5 |
HIGH
Network
|
nazgul
|
nostromo_nhttpd
|
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16279
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222494
|
9.8 |
CRITICAL
Network
|
nazgul
|
nostromo_nhttpd
|
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16278
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222495
|
7.8 |
HIGH
Local
|
eset
|
cyber_security endpoint_antivirus endpoint_security
|
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.
|
CWE-269
Improper Privilege Management
|
CVE-2019-16519
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222496
|
6.1 |
MEDIUM
Network
|
scadabr
|
scadabr
|
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16344
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222497
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16417
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222498
|
5.4 |
MEDIUM
Network
|
hrworks
|
hrworks
|
HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16416
|
2024-11-21 13:30 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222499
|
7.4 |
HIGH
Network
|
twitter
|
twitter_kit
|
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there …
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16263
|
2024-11-21 13:30 |
2019-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222500
|
6.5 |
MEDIUM
Network
|
kslabs
|
ksweb
|
KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
|
CWE-22
Path Traversal
|
CVE-2019-16198
|
2024-11-21 13:30 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|