|
224081
|
5.5 |
MEDIUM
Local
|
wtfutil
|
wtf
|
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsaf…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-15716
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224082
|
5.3 |
MEDIUM
Network
|
entropic_project
|
entropic
|
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
|
CWE-22
Path Traversal
|
CVE-2019-15714
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224083
|
6.1 |
MEDIUM
Network
|
my_calendar_project
|
my_calendar
|
The my-calendar plugin before 3.1.10 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15713
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224084
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-15702
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224085
|
8.8 |
HIGH
Network
|
bloodhound_project
|
bloodhound
|
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search …
|
CWE-78
OS Command
|
CVE-2019-15701
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224086
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15700
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224087
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
|
NVD-CWE-noinfo
|
CVE-2019-15698
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224088
|
8.8 |
HIGH
Network
|
butlerblog
|
wp-members
|
The wp-members plugin before 3.2.8 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15660
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224089
|
4.3 |
MEDIUM
Network
|
easyupdatesmanager
|
easy_updates_manager
|
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
|
NVD-CWE-noinfo
|
CVE-2019-15650
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224090
|
9.8 |
CRITICAL
Network
|
genetechsolutions
|
pie_register
|
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
|
CWE-89
SQL Injection
|
CVE-2019-15659
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|