|
223081
|
5.4 |
MEDIUM
Network
|
shapepress
|
wp_dsgvo_tools
|
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15777
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223082
|
6.1 |
MEDIUM
Network
|
webcraftic
|
simple_301_redirects-addon-bulk_uploader
|
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
|
CWE-601
Open Redirect
|
CVE-2019-15776
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223083
|
6.1 |
MEDIUM
Network
|
learning_courses_project
|
learning_courses
|
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15775
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223084
|
6.1 |
MEDIUM
Network
|
booking_project
|
booking
|
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15774
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223085
|
6.1 |
MEDIUM
Network
|
travel_management_project
|
travel_management
|
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15773
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223086
|
6.1 |
MEDIUM
Network
|
donations_project
|
donations
|
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15772
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223087
|
8.8 |
HIGH
Network
|
hallme
|
woocommerce_address_book
|
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
|
CWE-352
Origin Validation Error
|
CVE-2019-15770
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223088
|
8.8 |
HIGH
Network
|
haktansuren
|
handl_utm_grabber
|
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
|
CWE-352
Origin Validation Error
|
CVE-2019-15769
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223089
|
7.8 |
HIGH
Local
|
gnu
|
chess
|
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15767
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223090
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15759
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|