|
222351
|
6.1 |
MEDIUM
Network
|
flower_project
|
flower
|
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16926
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222352
|
6.1 |
MEDIUM
Network
|
flower_project
|
flower
|
Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing con…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16925
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222353
|
9.8 |
CRITICAL
Network
|
nsa
|
ghidra
|
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs i…
|
CWE-91
Blind XPath Injection
|
CVE-2019-16941
|
2024-11-21 13:31 |
2019-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222354
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdf
|
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16927
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222355
|
8.8 |
HIGH
Adjacent
|
nuvending
|
nulock
|
The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network) to take control of the lock.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-16924
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222356
|
6.1 |
MEDIUM
Network
|
kkcms_project
|
kkcms
|
kkcms 1.3 has jx.php?url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16923
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222357
|
5.3 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
|
NVD-CWE-noinfo
|
CVE-2019-16922
|
2024-11-21 13:31 |
2019-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222358
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive info…
|
CWE-665
Improper Initialization
|
CVE-2019-16921
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222359
|
7.5 |
HIGH
Network
|
reputeinfosystems
|
arforms
|
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
|
CWE-22
Path Traversal
|
CVE-2019-16902
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222360
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware dir-866l_firmware dir-652_firmware dhp-1565_firmware dir-855l_firmware dap-1533_firmware dir-862l_firmware dir-615_firmware dir-835_firmware dir-825_firmwa…
|
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device c…
|
CWE-78
OS Command
|
CVE-2019-16920
|
2024-11-21 13:31 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|