|
222261
|
9.8 |
CRITICAL
Network
|
10web
|
photo_gallery
|
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-16119
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222262
|
6.1 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16118
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222263
|
6.1 |
MEDIUM
Network
|
10web
|
photo_gallery
|
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16117
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222264
|
7.8 |
HIGH
Local
|
glyphandcog
|
xpdfreader
|
In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a cr…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16115
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222265
|
8.8 |
HIGH
Network
|
bludit
|
bludit
|
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
|
CWE-22
Path Traversal
|
CVE-2019-16113
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222266
|
5.3 |
MEDIUM
Network
|
plataformatec
|
devise
|
An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation…
|
NVD-CWE-noinfo
|
CVE-2019-16109
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222267
|
4.9 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
|
CWE-22
Path Traversal
|
CVE-2019-16105
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222268
|
6.1 |
MEDIUM
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16104
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222269
|
7.2 |
HIGH
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.
|
NVD-CWE-noinfo
|
CVE-2019-16103
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222270
|
9.8 |
CRITICAL
Network
|
silver-peak
|
unity_edgeconnect_sd-wan_firmware
|
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-16102
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|