|
223171
|
7.5 |
HIGH
Network
|
webarxsecurity
|
webarx
|
The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17214
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223172
|
6.1 |
MEDIUM
Network
|
webarxsecurity
|
webarx
|
The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17213
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223173
|
9.8 |
CRITICAL
Network
|
redis_wrapper_project
|
redis_wrapper
|
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17206
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223174
|
6.1 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17205
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223175
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17204
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223176
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17203
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223177
|
7.5 |
HIGH
Network
|
webpagetest
|
webpagetest
|
www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.
|
CWE-22
Path Traversal
|
CVE-2019-17199
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223178
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
|
CWE-89
SQL Injection
|
CVE-2019-17197
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223179
|
9.8 |
CRITICAL
Network
|
signal
|
private_messenger
|
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easie…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-17192
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223180
|
7.5 |
HIGH
Network
|
signal
|
private_messenger
|
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is…
|
CWE-863
Incorrect Authorization
|
CVE-2019-17191
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|