|
223621
|
9.8 |
CRITICAL
Network
|
py-lmdb_project
|
py-lmdb
|
An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy destination, leading to an invalid write operation. NOTE: this outcome occurs w…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16224
|
2024-11-21 13:30 |
2019-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223622
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16223
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223623
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16222
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223624
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows reflected XSS in the dashboard.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16221
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223625
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forwar…
|
CWE-601
Open Redirect
|
CVE-2019-16220
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223626
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in shortcode previews.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16219
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223627
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in stored comments.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16218
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223628
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16217
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223629
|
5.4 |
MEDIUM
Network
|
esri
|
arcgis_enterprise
|
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16193
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223630
|
5.7 |
MEDIUM
Network
|
libra
|
libra_core
|
Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attackers to interfere with code auditing by using a nonstandard line-break character f…
|
NVD-CWE-noinfo
|
CVE-2019-16214
|
2024-11-21 13:30 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|