|
219471
|
4.8 |
MEDIUM
Network
|
getawesomesupport
|
awesome_support
|
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20181
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219472
|
8.8 |
HIGH
Network
|
soplanning
|
soplanning
|
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
|
CWE-89
SQL Injection
|
CVE-2019-20179
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219473
|
6.5 |
MEDIUM
Network
|
peel
|
peel_shopping
|
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
|
CWE-352
Origin Validation Error
|
CVE-2019-20178
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219474
|
5.3 |
MEDIUM
Network
|
f5 apple canonical opensuse netapp
|
nginx xcode ubuntu_linux leap cloud_backup
|
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-20372
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219475
|
6.8 |
MEDIUM
Network
|
tablepress
|
tablepress
|
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application tha…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-20180
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219476
|
8.8 |
HIGH
Network
|
artica
|
pandora_fms
|
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?ope…
|
CWE-78
OS Command
|
CVE-2019-20224
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219477
|
9.1 |
CRITICAL
Network
|
freedesktop debian canonical opensuse
|
libbsd debian_linux ubuntu_linux leap
|
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20367
|
2024-11-21 13:38 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219478
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20366
|
2024-11-21 13:38 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219479
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20365
|
2024-11-21 13:38 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219480
|
6.1 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20364
|
2024-11-21 13:38 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|