|
222101
|
6.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
|
CWE-863
Incorrect Authorization
|
CVE-2019-19984
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222102
|
4.3 |
MEDIUM
Network
|
fastvelocity
|
minify
|
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs…
|
CWE-200
Information Exposure
|
CVE-2019-19983
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222103
|
5.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send…
|
CWE-287
Improper Authentication
|
CVE-2019-19982
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222104
|
5.4 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
|
CWE-352
Origin Validation Error
|
CVE-2019-19981
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222105
|
4.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administra…
|
NVD-CWE-noinfo
|
CVE-2019-19980
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222106
|
8.8 |
HIGH
Network
|
wp_maintenance_project
|
wp_maintenance
|
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with re…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-19979
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222107
|
9.8 |
CRITICAL
Network
|
libesmtp_project
|
libesmtp
|
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19977
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222108
|
7.5 |
HIGH
Network
|
upc
|
connect_box_eurodocsis_firmware
|
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Passwor…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19967
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222109
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-chann…
|
NVD-CWE-Other
|
CVE-2019-19963
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222110
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-19962
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|