|
222661
|
5.3 |
MEDIUM
Network
|
entropic_project
|
entropic
|
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
|
CWE-22
Path Traversal
|
CVE-2019-15714
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222662
|
6.1 |
MEDIUM
Network
|
my_calendar_project
|
my_calendar
|
The my-calendar plugin before 3.1.10 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15713
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222663
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-15702
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222664
|
8.8 |
HIGH
Network
|
bloodhound_project
|
bloodhound
|
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search …
|
CWE-78
OS Command
|
CVE-2019-15701
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222665
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15700
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222666
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
|
NVD-CWE-noinfo
|
CVE-2019-15698
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222667
|
8.8 |
HIGH
Network
|
butlerblog
|
wp-members
|
The wp-members plugin before 3.2.8 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15660
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222668
|
4.3 |
MEDIUM
Network
|
easyupdatesmanager
|
easy_updates_manager
|
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
|
NVD-CWE-noinfo
|
CVE-2019-15650
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222669
|
9.8 |
CRITICAL
Network
|
genetechsolutions
|
pie_register
|
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
|
CWE-89
SQL Injection
|
CVE-2019-15659
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222670
|
8.8 |
HIGH
Network
|
elearningfreak
|
insert_or_embed_articulate_content
|
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15649
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|