|
222981
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16781
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222982
|
8.2 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress lead…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16789
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222983
|
5.4 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16780
|
2024-11-21 13:31 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222984
|
7.5 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header …
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16786
|
2024-11-21 13:31 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222985
|
7.5 |
HIGH
Network
|
agendaless oracle debian fedoraproject redhat
|
waitress communications_cloud_native_core_network_function_cloud_native_environment debian_linux fedora openstack
|
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-16785
|
2024-11-21 13:31 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222986
|
9.8 |
CRITICAL
Network
|
beckhoff
|
twincat
|
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-16871
|
2024-11-21 13:31 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222987
|
5.9 |
MEDIUM
Network
|
rack_project fedoraproject opensuse
|
rack fedora leap
|
There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack session…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-16782
|
2024-11-21 13:31 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222988
|
9.8 |
CRITICAL
Network
|
google
|
tensorflow
|
In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from in…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2019-16778
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222989
|
5.9 |
MEDIUM
Network
|
excon_project opensuse debian
|
excon leap backports_sle debian_linux
|
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent req…
|
CWE-362
Race Condition
|
CVE-2019-16779
|
2024-11-21 13:31 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222990
|
9.8 |
CRITICAL
Network
|
skymee petwant
|
petalk_ai_firmware pf-103_firmware
|
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
|
CWE-78
OS Command
|
CVE-2019-16737
|
2024-11-21 13:31 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|