|
222581
|
5.6 |
MEDIUM
Local
|
linux debian opensuse netapp
|
linux_kernel debian_linux leap active_iq_performance_analytics_services service_processor baseboard_management_controller_firmware
|
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse …
|
CWE-200
Information Exposure
|
CVE-2019-15902
|
2024-11-21 13:29 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222582
|
6.1 |
MEDIUM
Network
|
nagios
|
log_server
|
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15898
|
2024-11-21 13:29 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222583
|
7.5 |
HIGH
Network
|
varnish_cache_project varnish-software debian
|
varnish_cache debian_linux
|
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests…
|
CWE-617
Reachable Assertion
|
CVE-2019-15892
|
2024-11-21 13:29 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222584
|
6.1 |
MEDIUM
Network
|
wpdownloadmanager
|
wordpress_download_manager
|
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15889
|
2024-11-21 13:29 |
2019-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222585
|
8.8 |
HIGH
Network
|
metagauss
|
profilegrid
|
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php …
|
CWE-94
Code Injection
|
CVE-2019-15873
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222586
|
9.8 |
CRITICAL
Network
|
wpbrigade
|
loginpress
|
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
|
CWE-89
SQL Injection
|
CVE-2019-15872
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222587
|
4.3 |
MEDIUM
Network
|
wpbrigade
|
loginpress
|
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
|
CWE-862
Missing Authorization
|
CVE-2019-15871
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222588
|
5.4 |
MEDIUM
Network
|
carspot_project
|
carspot
|
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15870
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222589
|
5.4 |
MEDIUM
Network
|
jobcareer_project
|
jobcareer
|
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15869
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222590
|
8.8 |
HIGH
Network
|
wpaffiliatemanager
|
affiliates_manager
|
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15868
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|