|
223311
|
7.2 |
HIGH
Network
|
halo
|
halo
|
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-19999
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223312
|
7.5 |
HIGH
Network
|
xiuno
|
xiunobbs
|
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
|
CWE-611
XXE
|
CVE-2019-19998
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223313
|
5.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
|
CWE-862
Missing Authorization
|
CVE-2019-19985
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223314
|
6.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
|
CWE-863
Incorrect Authorization
|
CVE-2019-19984
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223315
|
4.3 |
MEDIUM
Network
|
fastvelocity
|
minify
|
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs…
|
CWE-200
Information Exposure
|
CVE-2019-19983
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223316
|
5.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send…
|
CWE-287
Improper Authentication
|
CVE-2019-19982
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223317
|
5.4 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
|
CWE-352
Origin Validation Error
|
CVE-2019-19981
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223318
|
4.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administra…
|
NVD-CWE-noinfo
|
CVE-2019-19980
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223319
|
8.8 |
HIGH
Network
|
wp_maintenance_project
|
wp_maintenance
|
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with re…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-19979
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223320
|
9.8 |
CRITICAL
Network
|
libesmtp_project
|
libesmtp
|
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19977
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|