|
222741
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in shortcode previews.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16219
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222742
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in stored comments.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16218
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222743
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16217
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222744
|
5.4 |
MEDIUM
Network
|
esri
|
arcgis_enterprise
|
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16193
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222745
|
5.7 |
MEDIUM
Network
|
libra
|
libra_core
|
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character f…
|
NVD-CWE-noinfo
|
CVE-2019-16214
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222746
|
7.5 |
HIGH
Network
|
humanica
|
humatrix
|
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16106
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222747
|
6.5 |
MEDIUM
Network
|
misp
|
misp
|
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indicat…
|
CWE-269
Improper Privilege Management
|
CVE-2019-16202
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222748
|
9.8 |
CRITICAL
Network
|
doccms
|
doccms
|
upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbitrary PHP code through module management files, as demonstrated by a .php file i…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16192
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222749
|
7.5 |
HIGH
Network
|
limesurvey
|
limesurvey
|
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16187
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222750
|
7.2 |
HIGH
Network
|
limesurvey
|
limesurvey
|
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16186
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|