|
222621
|
7.5 |
HIGH
Network
|
bold-themes
|
bold_page_builder
|
The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data.
|
NVD-CWE-noinfo
|
CVE-2019-15821
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222622
|
6.1 |
MEDIUM
Network
|
login_or_logout_menu_item_project
|
login_or_logout_menu_item
|
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
|
CWE-601
Open Redirect
|
CVE-2019-15820
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222623
|
9.8 |
CRITICAL
Network
|
restaurant_reservations_project
|
restaurant_reservations
|
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15819
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222624
|
6.1 |
MEDIUM
Network
|
webcraftic
|
simple_301_redirects
|
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
|
CWE-601
Open Redirect
|
CVE-2019-15818
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222625
|
6.1 |
MEDIUM
Network
|
realestateconnected
|
easy_property_listings
|
The easy-property-listings plugin before 3.4 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15817
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222626
|
7.5 |
HIGH
Network
|
wpexpertdeveloper
|
wp_private_content_plus
|
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.
|
CWE-79 CWE-601
Cross-site Scripting Open Redirect
|
CVE-2019-15816
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222627
|
6.1 |
MEDIUM
Network
|
domainmod
|
domainmod
|
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15811
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222628
|
4.7 |
MEDIUM
Local
|
linux redhat debian
|
linux_kernel enterprise_linux debian_linux
|
In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-15807
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222629
|
9.8 |
CRITICAL
Network
|
commscope
|
tr4400_firmware
|
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded passwo…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-15806
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222630
|
9.8 |
CRITICAL
Network
|
commscope
|
tr4400_firmware
|
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded passwo…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2019-15805
|
2024-11-21 13:29 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|