|
223591
|
7.8 |
HIGH
Local
|
infoway
|
social_photo_gallery
|
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not chec…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14467
|
2024-11-21 13:26 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223592
|
9.8 |
CRITICAL
Network
|
vocabularyserver
|
tematres
|
TemaTres 3.0 allows remote unprivileged users to create an administrator account
|
NVD-CWE-noinfo
|
CVE-2019-14345
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223593
|
5.4 |
MEDIUM
Network
|
vocabularyserver
|
tematres
|
TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14343
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223594
|
5.5 |
MEDIUM
Local
|
intel netapp
|
graphics_driver cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire_baseboard_management_controller_firmware
|
Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-20
Improper Input Validation
|
CVE-2019-14591
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223595
|
5.5 |
MEDIUM
Local
|
intel netapp
|
graphics_driver cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire_baseboard_management_controller_firmware
|
Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via local access.
|
CWE-269
Improper Privilege Management
|
CVE-2019-14590
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223596
|
5.5 |
MEDIUM
Local
|
intel netapp
|
graphics_driver cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire_baseboard_management_controller_firmware
|
Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14574
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223597
|
7.8 |
HIGH
Local
|
intel
|
software_guard_extensions_sdk
|
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service vi…
|
CWE-20
Improper Input Validation
|
CVE-2019-14566
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223598
|
7.8 |
HIGH
Local
|
intel
|
software_guard_extensions_sdk
|
Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclos…
|
CWE-665
Improper Initialization
|
CVE-2019-14565
|
2024-11-21 13:26 |
2019-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223599
|
7.5 |
HIGH
Network
|
slack-chat_project
|
slack-chat
|
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
|
CWE-200
Information Exposure
|
CVE-2019-14367
|
2024-11-21 13:26 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223600
|
7.5 |
HIGH
Network
|
slack
|
wp_slacksync
|
WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
|
CWE-200
Information Exposure
|
CVE-2019-14366
|
2024-11-21 13:26 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|