|
222331
|
6.1 |
MEDIUM
Network
|
booking_project
|
booking
|
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15774
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222332
|
6.1 |
MEDIUM
Network
|
travel_management_project
|
travel_management
|
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15773
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222333
|
6.1 |
MEDIUM
Network
|
donations_project
|
donations
|
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15772
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222334
|
8.8 |
HIGH
Network
|
hallme
|
woocommerce_address_book
|
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
|
CWE-352
Origin Validation Error
|
CVE-2019-15770
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222335
|
8.8 |
HIGH
Network
|
haktansuren
|
handl_utm_grabber
|
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
|
CWE-352
Origin Validation Error
|
CVE-2019-15769
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222336
|
7.8 |
HIGH
Local
|
gnu
|
chess
|
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15767
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222337
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15759
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222338
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-se…
|
CWE-617
Reachable Assertion
|
CVE-2019-15758
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222339
|
6.5 |
MEDIUM
Network
|
libmirage_project
|
libmirage
|
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15757
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222340
|
7.8 |
HIGH
Local
|
docker apache
|
docker geode
|
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15752
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|