|
223841
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
|
NVD-CWE-noinfo
|
CVE-2019-17673
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223842
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17672
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223843
|
5.3 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
|
CWE-200
Information Exposure
|
CVE-2019-17671
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223844
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17670
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223845
|
9.8 |
CRITICAL
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17669
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223846
|
6.8 |
MEDIUM
Physics
|
samsung
|
galaxy_s10_firmware note_10_firmware
|
Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involving a third-party screen protector.
|
NVD-CWE-noinfo
|
CVE-2019-17668
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223847
|
5.4 |
MEDIUM
Network
|
comtechtel
|
h8_heights_remote_gateway_firmware
|
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17667
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223848
|
8.8 |
HIGH
Adjacent
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17666
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223849
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17611
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223850
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17610
|
2024-11-21 13:32 |
2019-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|