|
223041
|
6.1 |
MEDIUM
Network
|
oldstreetsolutions
|
live_input_macros
|
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15233
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223042
|
6.1 |
MEDIUM
Network
|
yofla
|
360_product_rotation
|
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15082
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223043
|
7.8 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrectly backported to the earlier longterm kernels, introducing a new vulnerability …
|
CWE-416
Use After Free
|
CVE-2019-15239
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223044
|
6.1 |
MEDIUM
Network
|
getflightpath
|
flightpath
|
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15227
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223045
|
7.4 |
HIGH
Network
|
roundcube fedoraproject
|
webmail fedora
|
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
|
NVD-CWE-noinfo
|
CVE-2019-15237
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223046
|
9.8 |
CRITICAL
Network
|
live555
|
streaming_media
|
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and …
|
CWE-416
Use After Free
|
CVE-2019-15232
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223047
|
8.8 |
HIGH
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially craft…
|
CWE-352
Origin Validation Error
|
CVE-2019-15229
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223048
|
5.4 |
MEDIUM
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated acc…
|
CWE-79
Cross-site Scripting
|
CVE-2019-15228
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223049
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression implementation. A remote attacker may send a request with a very long URI to r…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15225
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223050
|
9.8 |
CRITICAL
Network
|
rest-client_project
|
rest-client
|
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
|
CWE-94
Code Injection
|
CVE-2019-15224
|
2024-11-21 13:28 |
2019-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|