|
223321
|
8.8 |
HIGH
Network
|
bloodhound_project
|
bloodhound
|
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search …
|
CWE-78
OS Command
|
CVE-2019-15701
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223322
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15700
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223323
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
|
NVD-CWE-noinfo
|
CVE-2019-15698
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223324
|
8.8 |
HIGH
Network
|
butlerblog
|
wp-members
|
The wp-members plugin before 3.2.8 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15660
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223325
|
4.3 |
MEDIUM
Network
|
easyupdatesmanager
|
easy_updates_manager
|
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
|
NVD-CWE-noinfo
|
CVE-2019-15650
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223326
|
9.8 |
CRITICAL
Network
|
genetechsolutions
|
pie_register
|
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
|
CWE-89
SQL Injection
|
CVE-2019-15659
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223327
|
8.8 |
HIGH
Network
|
elearningfreak
|
insert_or_embed_articulate_content
|
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15649
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223328
|
6.5 |
MEDIUM
Network
|
elearningfreak
|
insert_or_embed_articulate_content
|
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
|
CWE-287 CWE-352 CWE-22 CWE-862
Improper Authentication Origin Validation Error Path Traversal Missing Authorization
|
CVE-2019-15648
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223329
|
8.8 |
HIGH
Network
|
groundhogg
|
groundhogg
|
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
|
CWE-94
Code Injection
|
CVE-2019-15647
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223330
|
9.8 |
CRITICAL
Network
|
carrcommunications
|
rsvpmaker
|
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-15646
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|