|
218811
|
6.1 |
MEDIUM
Network
|
premiumwpsuite
|
easy_redirect_manager
|
The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is mishandled during log viewing at the templates/admin/redirect-log.php URI.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6267
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218812
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6286
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218813
|
6.5 |
MEDIUM
Network
|
yaml-cpp_project
|
yaml-cpp
|
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML …
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-6285
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218814
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6284
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218815
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6283
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218816
|
5.4 |
MEDIUM
Network
|
jpress
|
jpress
|
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6278
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218817
|
9.8 |
CRITICAL
Network
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6259
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218818
|
7.7 |
HIGH
Network
|
std42
|
elfinder
|
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-6257
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218819
|
8.1 |
HIGH
Network
|
gnome wpewebkit webkitgtk fedoraproject canonical opensuse
|
epiphany wpe_webkit webkitgtk fedora ubuntu_linux leap
|
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a…
|
NVD-CWE-noinfo
|
CVE-2019-6251
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218820
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
|
CWE-352
Origin Validation Error
|
CVE-2019-6249
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|