|
211641
|
7.5 |
HIGH
Network
|
mishubd
|
wp_human_resource_management
|
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.
|
CWE-862
Missing Authorization
|
CVE-2019-9574
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211642
|
7.5 |
HIGH
Network
|
mishubd
|
wp_human_resource_management
|
The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications.
|
CWE-19
Data Processing Errors
|
CVE-2019-9573
|
2024-11-21 13:51 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211643
|
7.2 |
HIGH
Network
|
schoolcms
|
schoolcms
|
SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type t…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9572
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211644
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9570
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211645
|
6.5 |
MEDIUM
Network
|
incsub
|
forminator
|
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delet…
|
CWE-89
SQL Injection
|
CVE-2019-9568
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211646
|
6.1 |
MEDIUM
Network
|
incsub
|
forminator
|
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9567
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211647
|
9.8 |
CRITICAL
Network
|
flarumchina
|
flarumchina
|
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
|
CWE-89
SQL Injection
|
CVE-2019-9566
|
2024-11-21 13:51 |
2019-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211648
|
9.1 |
CRITICAL
Network
|
druide
|
antidote
|
Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or…
|
NVD-CWE-noinfo
|
CVE-2019-9565
|
2024-11-21 13:51 |
2019-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211649
|
7.5 |
HIGH
Network
|
bluemind
|
bluemind
|
In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
|
CWE-19
Data Processing Errors
|
CVE-2019-9563
|
2024-11-21 13:51 |
2019-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211650
|
9.8 |
CRITICAL
Network
|
eloan_project
|
eloan
|
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-9552
|
2024-11-21 13:51 |
2019-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|