|
224741
|
6.1 |
MEDIUM
Network
|
donations_project
|
donations
|
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
|
CWE-601
Open Redirect
|
CVE-2019-15772
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224742
|
8.8 |
HIGH
Network
|
hallme
|
woocommerce_address_book
|
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
|
CWE-352
Origin Validation Error
|
CVE-2019-15770
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224743
|
8.8 |
HIGH
Network
|
haktansuren
|
handl_utm_grabber
|
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
|
CWE-352
Origin Validation Error
|
CVE-2019-15769
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224744
|
7.8 |
HIGH
Local
|
gnu
|
chess
|
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15767
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224745
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15759
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224746
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-se…
|
CWE-617
Reachable Assertion
|
CVE-2019-15758
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224747
|
6.5 |
MEDIUM
Network
|
libmirage_project
|
libmirage
|
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15757
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224748
|
7.8 |
HIGH
Local
|
docker apache
|
docker geode
|
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15752
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224749
|
9.1 |
CRITICAL
Network
|
openstack
|
os-vif
|
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15753
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224750
|
7.8 |
HIGH
Local
|
cloudberrylab
|
backup
|
CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup action script that e…
|
CWE-269
Improper Privilege Management
|
CVE-2019-15720
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|