|
222991
|
8.8 |
HIGH
Network
|
wp_svg_icons_project
|
wp_svg_icons
|
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads…
|
CWE-352
Origin Validation Error
|
CVE-2019-14216
|
2024-11-21 13:26 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222992
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. …
|
CWE-22
Path Traversal
|
CVE-2019-14530
|
2024-11-21 13:26 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222993
|
7.4 |
HIGH
Network
|
uidai
|
maadhaar
|
The mAadhaar application 1.2.7 for Android lacks SSL Certificate Validation, leading to man-in-the-middle attacks against requests for FAQs or Help.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-14516
|
2024-11-21 13:26 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222994
|
2.4 |
LOW
Physics
|
real-sec
|
bc_vault_firmware
|
On BC Vault devices, a side channel for the row-based SSD1309 OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a par…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14359
|
2024-11-21 13:26 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222995
|
2.4 |
LOW
Physics
|
mooltipass
|
mooltipass_mini_firmware
|
On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a part…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14357
|
2024-11-21 13:26 |
2019-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222996
|
2.4 |
LOW
Physics
|
shapeshift
|
keepkey_firmware
|
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a p…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14355
|
2024-11-21 13:26 |
2019-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222997
|
2.4 |
LOW
Physics
|
ledger
|
nano_s_firmware nano_x_firmware
|
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowi…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-14354
|
2024-11-21 13:26 |
2019-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222998
|
6.5 |
MEDIUM
Network
|
openstack canonical redhat debian
|
nova ubuntu_linux openstack debian_linux
|
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external excepti…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-14433
|
2024-11-21 13:26 |
2019-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222999
|
6.5 |
MEDIUM
Network
|
aptana
|
jaxer
|
Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability allows a remote attacker to read internal files on the server via …
|
CWE-22
Path Traversal
|
CVE-2019-14312
|
2024-11-21 13:26 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223000
|
9.8 |
CRITICAL
Network
|
djangoproject fedoraproject debian
|
django fedora debian_linux
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.…
|
CWE-89
SQL Injection
|
CVE-2019-14234
|
2024-11-21 13:26 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|