|
211301
|
7.5 |
HIGH
Network
|
gnu opensuse
|
tar leap
|
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9923
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211302
|
6.1 |
MEDIUM
Network
|
get-simple.
|
getsimplecms
|
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
|
CWE-601
Open Redirect
|
CVE-2019-9915
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211303
|
6.1 |
MEDIUM
Network
|
yop-poll
|
yop-poll
|
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9914
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211304
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9913
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211305
|
6.1 |
MEDIUM
Network
|
codecabin
|
wp_go_maps
|
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9912
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211306
|
6.1 |
MEDIUM
Network
|
nextscripts
|
social_networks_auto_poster
|
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9911
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211307
|
6.1 |
MEDIUM
Network
|
king-theme
|
kingcomposer
|
The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9910
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211308
|
6.1 |
MEDIUM
Network
|
givewp
|
givewp
|
The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9909
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211309
|
6.1 |
MEDIUM
Network
|
hivewebstudios
|
font_organizer
|
The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9908
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211310
|
6.5 |
MEDIUM
Network
|
graphviz
|
graphviz
|
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in l…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9904
|
2024-11-21 13:52 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|