|
223031
|
7.5 |
HIGH
Network
|
convertplug
|
convertplus
|
The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request for variants.
|
NVD-CWE-noinfo
|
CVE-2019-15863
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223032
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15860
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223033
|
8.8 |
HIGH
Network
|
webcraftic
|
woody_ad_snippets
|
admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthenticated options import, as demonstrated by storing an XSS payload for remote code e…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15858
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223034
|
7.5 |
HIGH
Network
|
gnu opensuse
|
gcc leap
|
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number …
|
CWE-331
Insufficient Entropy
|
CVE-2019-15847
|
2024-11-21 13:29 |
2019-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223035
|
6.1 |
MEDIUM
Network
|
easy_pdf_restaurant_menu_upload_project
|
easy_pdf_restaurant_menu_upload
|
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15842
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223036
|
8.8 |
HIGH
Network
|
facebook
|
facebook_for_woocommerce
|
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
|
CWE-352
Origin Validation Error
|
CVE-2019-15841
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223037
|
8.8 |
HIGH
Network
|
facebook
|
facebook_for_woocommerce
|
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15840
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223038
|
7.5 |
HIGH
Network
|
shaosina
|
sina_extension_for_elementor
|
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
|
CWE-22 CWE-829
Path Traversal Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2019-15839
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223039
|
6.1 |
MEDIUM
Network
|
kunalnagar
|
custom_404_pro
|
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15838
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223040
|
5.4 |
MEDIUM
Network
|
bitwise-it
|
webp_express
|
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15837
|
2024-11-21 13:29 |
2019-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|