|
223091
|
9.8 |
CRITICAL
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
|
CWE-94
Code Injection
|
CVE-2019-14965
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
7.5 |
HIGH
Network
|
telenav
|
scout_gps_link
|
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it eas…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-14951
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14947
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14946
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14945
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14950
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
6.1 |
MEDIUM
Network
|
wpseeds
|
wp_database_backup
|
The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14949
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
5.4 |
MEDIUM
Network
|
najeebmedia
|
ppom_for_woocommerce
|
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14948
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
7.5 |
HIGH
Network
|
humanica
|
humatrix_7
|
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resum…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-14932
|
2024-11-21 13:27 |
2019-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
6.5 |
MEDIUM
Network
|
spdk
|
storage_performance_development_kit
|
In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input.
|
NVD-CWE-noinfo
|
CVE-2019-14940
|
2024-11-21 13:27 |
2019-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|