|
223111
|
6.1 |
MEDIUM
Network
|
zoho
|
salesiq
|
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15644
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223112
|
6.1 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_faq
|
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15643
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223113
|
4.4 |
MEDIUM
Local
|
linux debian opensuse
|
linux_kernel debian_linux leap
|
An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfr…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15666
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223114
|
7.3 |
HIGH
Network
|
connect-pg-simple_project
|
connect-pg-simple
|
connect-pg-simple before 6.0.1 allows SQL injection if tableName or schemaName is untrusted data.
|
CWE-89
SQL Injection
|
CVE-2019-15658
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223115
|
9.8 |
CRITICAL
Network
|
eslint-utils_project
|
eslint-utils
|
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2019-15657
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223116
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_e…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15651
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223117
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation stat…
|
CWE-94
Code Injection
|
CVE-2019-15642
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223118
|
6.5 |
MEDIUM
Network
|
webmin
|
webmin
|
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
|
CWE-611
XXE
|
CVE-2019-15641
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223119
|
7.5 |
HIGH
Network
|
limesurvey
|
limesurvey
|
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
|
CWE-20
Improper Input Validation
|
CVE-2019-15640
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223120
|
8.1 |
HIGH
Network
|
tableau
|
tableau_server tableau_desktop tableau_reader tableau_public_desktop
|
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau …
|
CWE-611
XXE
|
CVE-2019-15637
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|