|
221951
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
|
NVD-CWE-noinfo
|
CVE-2019-17673
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221952
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17672
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221953
|
5.3 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
|
CWE-200
Information Exposure
|
CVE-2019-17671
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221954
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17670
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221955
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17669
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221956
|
6.8 |
MEDIUM
Physics
|
samsung
|
galaxy_s10_firmware note_10_firmware
|
Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involving a third-party screen protector.
|
NVD-CWE-noinfo
|
CVE-2019-17668
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221957
|
5.4 |
MEDIUM
Network
|
comtechtel
|
h8_heights_remote_gateway_firmware
|
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17667
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221958
|
8.8 |
HIGH
Adjacent
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17666
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221959
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17611
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221960
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17610
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|