|
213021
|
5.5 |
MEDIUM
Local
|
boolector_project
|
boolector
|
In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_assumptions or btor_delete.
|
CWE-416
Use After Free
|
CVE-2019-7560
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213022
|
5.5 |
MEDIUM
Local
|
btor2tools_project
|
btor2tools
|
In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to an out of bounds write in pusht_bfr.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-7559
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213023
|
7.8 |
HIGH
Local
|
sqlalchemy debian opensuse redhat oracle
|
sqlalchemy debian_linux leap backports_sle enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux communications_operations_monitor
|
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
|
CWE-89
SQL Injection
|
CVE-2019-7548
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213024
|
4.8 |
MEDIUM
Network
|
topnew
|
sidu
|
An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name containing an XSS Payload, leading to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7547
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213025
|
6.1 |
MEDIUM
Network
|
topnew
|
sidu
|
An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7546
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213026
|
5.4 |
MEDIUM
Network
|
dbninja
|
dbninja
|
In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7545
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213027
|
5.4 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name Field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7544
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213028
|
6.1 |
MEDIUM
Network
|
kindsoft
|
kindeditor
|
In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7543
|
2024-11-21 13:48 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213029
|
6.1 |
MEDIUM
Network
|
parallax_scroll_project
|
parallax_scroll
|
In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7413
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213030
|
9.8 |
CRITICAL
Network
|
ps_phpcaptcha_wp_project
|
ps_phpcaptcha_wp
|
The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
|
CWE-20
Improper Input Validation
|
CVE-2019-7412
|
2024-11-21 13:48 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|