|
222691
|
9.8 |
CRITICAL
Network
|
linux canonical
|
linux_kernel ubuntu_linux
|
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
|
CWE-415
Double Free
|
CVE-2019-15504
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222692
|
6.1 |
MEDIUM
Network
|
hackmd
|
codimd
|
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15499
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222693
|
8.8 |
HIGH
Network
|
getvera
|
vera_edge_firmware
|
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/…
|
CWE-88
Argument Injection
|
CVE-2019-15498
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222694
|
8.8 |
HIGH
Network
|
codection
|
import_users_from_csv_with_meta
|
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15329
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222695
|
6.1 |
MEDIUM
Network
|
codection
|
import_users_from_csv_with_meta
|
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15328
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222696
|
6.1 |
MEDIUM
Network
|
codection
|
import_users_from_csv_with_meta
|
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15327
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222697
|
7.5 |
HIGH
Network
|
codection
|
import_users_from_csv_with_meta
|
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-15326
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222698
|
7.5 |
HIGH
Network
|
galliumos
|
galliumos
|
In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/ptrace_scope to 1, which might increase risk because of the appearance that a pr…
|
NVD-CWE-noinfo
|
CVE-2019-15325
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222699
|
6.1 |
MEDIUM
Network
|
wpsupportplus
|
wp_support_plus_responsive_ticket_system
|
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15331
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222700
|
7.5 |
HIGH
Network
|
webp_express_project
|
webp_express
|
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
|
NVD-CWE-noinfo
|
CVE-2019-15330
|
2024-11-21 13:28 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|