|
222591
|
8.8 |
HIGH
Network
|
omaksolutions
|
slick-popup
|
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-15867
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222592
|
8.8 |
HIGH
Network
|
crelly_slider_project
|
crelly_slider
|
The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_ajax_crellyslider_importSlider.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15866
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222593
|
8.8 |
HIGH
Network
|
holest
|
breadcrumbs_by_menu
|
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15865
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222594
|
6.1 |
MEDIUM
Network
|
holest
|
breadcrumbs_by_menu
|
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15864
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222595
|
7.5 |
HIGH
Network
|
convertplug
|
convertplus
|
The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants.
|
NVD-CWE-noinfo
|
CVE-2019-15863
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222596
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15860
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222597
|
8.8 |
HIGH
Network
|
webcraftic
|
woody_ad_snippets
|
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code e…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15858
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222598
|
7.5 |
HIGH
Network
|
gnu opensuse
|
gcc leap
|
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number …
|
CWE-331
Insufficient Entropy
|
CVE-2019-15847
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222599
|
6.1 |
MEDIUM
Network
|
easy_pdf_restaurant_menu_upload_project
|
easy_pdf_restaurant_menu_upload
|
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15842
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222600
|
8.8 |
HIGH
Network
|
facebook
|
facebook_for_woocommerce
|
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
|
CWE-352
Origin Validation Error
|
CVE-2019-15841
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|