|
222711
|
9.1 |
CRITICAL
Network
|
eclipse redhat
|
openj9 enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux satellite
|
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
|
CWE-269
Improper Privilege Management
|
CVE-2019-17631
|
2024-11-21 13:32 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222712
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSa…
|
CWE-352
Origin Validation Error
|
CVE-2019-17676
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222713
|
8.8 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
|
CWE-352 CWE-843
Origin Validation Error Type Confusion
|
CVE-2019-17675
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222714
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17674
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222715
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
|
NVD-CWE-noinfo
|
CVE-2019-17673
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222716
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17672
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222717
|
5.3 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
|
CWE-200
Information Exposure
|
CVE-2019-17671
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222718
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17670
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222719
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17669
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222720
|
6.8 |
MEDIUM
Physics
|
samsung
|
galaxy_s10_firmware note_10_firmware
|
Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involving a third-party screen protector.
|
NVD-CWE-noinfo
|
CVE-2019-17668
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|