|
223801
|
7.8 |
HIGH
Local
|
trendmicro
|
antivirus_\+_security_2019 internet_security_2019 maximum_security_2019 premium_security_2019
|
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious ser…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2019-14685
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223802
|
5.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
|
CWE-200
Information Exposure
|
CVE-2019-15045
|
2024-11-21 13:27 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223803
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14687
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223804
|
7.8 |
HIGH
Local
|
trendmicro
|
password_manager
|
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This proc…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-14684
|
2024-11-21 13:27 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223805
|
7.5 |
HIGH
Network
|
vanderbilt
|
redcap
|
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a …
|
CWE-89
SQL Injection
|
CVE-2019-14937
|
2024-11-21 13:27 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223806
|
8.8 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
|
CWE-78
OS Command
|
CVE-2019-14923
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223807
|
6.1 |
MEDIUM
Network
|
kunalnagar
|
custom_404_pro
|
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14789
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223808
|
8.8 |
HIGH
Network
|
tribulant
|
newsletters
|
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the s…
|
CWE-22
Path Traversal
|
CVE-2019-14788
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223809
|
6.5 |
MEDIUM
Network
|
rankmath
|
seo
|
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
|
CWE-862
Missing Authorization
|
CVE-2019-14786
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223810
|
6.1 |
MEDIUM
Network
|
codepeople
|
cp_contact_form_with_paypal
|
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14784
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|