|
211131
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9925
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
7.8 |
HIGH
Local
|
gnu debian opensuse netapp canonical
|
bash debian_linux leap solidfire hci_management_node ubuntu_linux
|
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.
|
CWE-862
Missing Authorization
|
CVE-2019-9924
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
7.5 |
HIGH
Network
|
gnu opensuse
|
tar leap
|
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9923
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
6.1 |
MEDIUM
Network
|
get-simple.
|
getsimplecms
|
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
|
CWE-601
Open Redirect
|
CVE-2019-9915
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
6.1 |
MEDIUM
Network
|
yop-poll
|
yop-poll
|
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9914
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9913
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
6.1 |
MEDIUM
Network
|
codecabin
|
wp_go_maps
|
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9912
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
6.1 |
MEDIUM
Network
|
nextscripts
|
social_networks_auto_poster
|
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9911
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
6.1 |
MEDIUM
Network
|
king-theme
|
kingcomposer
|
The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9910
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
6.1 |
MEDIUM
Network
|
givewp
|
givewp
|
The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9909
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|