|
224511
|
9.8 |
CRITICAL
Network
|
awplife
|
contact_form_widget
|
The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.
|
CWE-89
SQL Injection
|
CVE-2019-17072
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224512
|
6.1 |
MEDIUM
Network
|
realbigplugins
|
client_dash
|
The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17071
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224513
|
6.1 |
MEDIUM
Network
|
lqd
|
liquid_speech_balloon
|
The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17070
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224514
|
6.5 |
MEDIUM
Network
|
koji_project
|
koji
|
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
|
CWE-22
Path Traversal
|
CVE-2019-17109
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224515
|
4.3 |
MEDIUM
Network
|
zohocorp
|
manageengine_datasecurity_plus
|
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server …
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-17112
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224516
|
7.8 |
HIGH
Local
|
openbsd netapp siemens
|
openssh cloud_backup steelstore_cloud_integrated_storage scalance_x204rna_firmware scalance_x204rna_ecc_firmware
|
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-16905
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224517
|
6.1 |
MEDIUM
Network
|
openproject
|
openproject
|
An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17092
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224518
|
7.5 |
HIGH
Network
|
netreo
|
omnicenter
|
Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters and parameter name of the login page through a GET request. The injection allows…
|
CWE-89
SQL Injection
|
CVE-2019-17128
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224519
|
9.8 |
CRITICAL
Network
|
kramerav
|
viaware
|
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17124
|
2024-11-21 13:31 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224520
|
8.8 |
HIGH
Network
|
fiberhome
|
hg2201t_firmware
|
/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code execution.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17186
|
2024-11-21 13:31 |
2019-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|