|
223471
|
5.4 |
MEDIUM
Network
|
nchsoftware
|
express_accounts_accounting
|
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16330
|
2024-11-21 13:30 |
2019-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223472
|
7.3 |
HIGH
Network
|
url_redirect_project
|
url_redirect
|
The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-16682
|
2024-11-21 13:30 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223473
|
5.4 |
MEDIUM
Network
|
pixelite
|
events_manager
|
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcode…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16523
|
2024-11-21 13:30 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223474
|
4.8 |
MEDIUM
Network
|
eu_cookie_law_project
|
eu_cookie_law
|
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displa…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16522
|
2024-11-21 13:30 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223475
|
6.1 |
MEDIUM
Network
|
managewp
|
broken_link_checker
|
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The fi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16521
|
2024-11-21 13:30 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223476
|
5.4 |
MEDIUM
Network
|
semperplugins
|
all_in_one_seo_pack
|
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plu…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16520
|
2024-11-21 13:30 |
2019-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223477
|
5.4 |
MEDIUM
Network
|
nchsoftware
|
express_invoice
|
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Cu…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16282
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223478
|
7.5 |
HIGH
Network
|
nazgul
|
nostromo_nhttpd
|
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16279
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223479
|
9.8 |
CRITICAL
Network
|
nazgul
|
nostromo_nhttpd
|
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
|
CWE-22
Path Traversal
|
CVE-2019-16278
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223480
|
7.8 |
HIGH
Local
|
eset
|
cyber_security endpoint_antivirus endpoint_security
|
ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an undocumented feature in scheduled tasks.
|
CWE-269
Improper Privilege Management
|
CVE-2019-16519
|
2024-11-21 13:30 |
2019-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|