CVE-2019-14000 to CVE-2019-14999
184 CVEs with public proof-of-concept exploits.
- CVE-2019-140401 PoCUsing memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in…
- CVE-2019-140411 PoCDuring listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer…
- CVE-2019-140791 PoCAccess to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the first place…
- CVE-2019-142054 PoCsA Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve…
- CVE-2019-142064 PoCsAn Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete…
- CVE-2019-142161 PoCAn issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress.…
- CVE-2019-142201 PoCAn issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a…
- CVE-2019-142212 PoCs1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
- CVE-2019-142221 PoCAn issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to…
- CVE-2019-142232 PoCsAn issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable…
- CVE-2019-142241 PoCAn issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications,…
- CVE-2019-142251 PoCOX App Suite 7.10.1 and 7.10.2 allows SSRF.
- CVE-2019-142261 PoCOX App Suite through 7.10.2 has Insecure Permissions.
- CVE-2019-142272 PoCsOX App Suite 7.10.1 and 7.10.2 allows XSS.
- CVE-2019-142281 PoCXavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at…
- CVE-2019-142302 PoCsAn issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the…
- CVE-2019-142312 PoCsAn issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in…
- CVE-2019-142344 PoCsAn issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key…
- CVE-2019-142453 PoCsIn CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as…
- CVE-2019-142463 PoCsIn CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin…
- CVE-2019-142481 PoCIn libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list,…
- CVE-2019-142501 PoCAn issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not…
- CVE-2019-142512 PoCsAn issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server…
- CVE-2019-142521 PoCAn issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, one is able to…
- CVE-2019-142531 PoCAn issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and perform a query on…
- CVE-2019-142541 PoCAn issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are multiple SQL…
- CVE-2019-142571 PoCpyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are…
- CVE-2019-142581 PoCThe XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
- CVE-2019-142601 PoCOn the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input…
- CVE-2019-142673 PoCsPDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
- CVE-2019-1427110 PoCsIn Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility…
- CVE-2019-142771 PoCAxway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML…
- CVE-2019-142801 PoCIn some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was…
- CVE-2019-1428738 PoCsIn Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules,…
- CVE-2019-142882 PoCsAn issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one…
- CVE-2019-142892 PoCsAn issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the…
- CVE-2019-142902 PoCsAn issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for…
- CVE-2019-142912 PoCsAn issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for…
- CVE-2019-142922 PoCsAn issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for…
- CVE-2019-142932 PoCsAn issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for…
- CVE-2019-142942 PoCsAn issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out…
- CVE-2019-142951 PoCAn Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service…
- CVE-2019-142961 PoCcanUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application…
- CVE-2019-142971 PoCVeeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in…
- CVE-2019-142981 PoCVeeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in…
- CVE-2019-143123 PoCsAptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This vulnerability…
- CVE-2019-143141 PoCA SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this…
- CVE-2019-143191 PoCThe TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes.…
- CVE-2019-143227 PoCsIn Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
- CVE-2019-143261 PoCAn issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root…
- CVE-2019-143282 PoCsThe Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
- CVE-2019-143291 PoCAn issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in Create Task. A…
- CVE-2019-143301 PoCAn issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A…
- CVE-2019-143311 PoCAn issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A…
- CVE-2019-143321 PoCAn issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as…
- CVE-2019-143331 PoCAn issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a pre-authenticated denial of service…
- CVE-2019-143341 PoCAn issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated…
- CVE-2019-143361 PoCAn issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated dump of all of the…
- CVE-2019-143371 PoCAn issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the…
- CVE-2019-143381 PoCAn issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action=…
- CVE-2019-143393 PoCsThe ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict…
- CVE-2019-143431 PoCTemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
- CVE-2019-143462 PoCsInternal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
- CVE-2019-143472 PoCsInternal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator…
- CVE-2019-143482 PoCsThe BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the…
- CVE-2019-143491 PoCEspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for…
- CVE-2019-143501 PoCEspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malicious attacker can…
- CVE-2019-143511 PoCEspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by…
- CVE-2019-143531 PoCOn Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based…
- CVE-2019-143631 PoCA stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an…
- CVE-2019-143681 PoCExiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
- CVE-2019-143691 PoCExiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer…
- CVE-2019-143701 PoCIn Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.
- CVE-2019-143711 PoCAn issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to…
- CVE-2019-143721 PoCIn Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
- CVE-2019-143731 PoCAn issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a…
- CVE-2019-143781 PoCip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the…
- CVE-2019-143791 PoCSubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of…
- CVE-2019-144223 PoCsAn issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which…
- CVE-2019-144231 PoCA Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote…
- CVE-2019-144241 PoCA Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote…
- CVE-2019-144271 PoCXSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted…
- CVE-2019-144301 PoCplugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
- CVE-2019-144392 PoCsA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled…
- CVE-2019-144411 PoCAn issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as…
- CVE-2019-144421 PoCIn mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU…
- CVE-2019-144431 PoCAn issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a…
- CVE-2019-144441 PoCapply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation…
- CVE-2019-144501 PoCA directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows for the creation…
- CVE-2019-144672 PoCsThe Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in…
- CVE-2019-144703 PoCscosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the…
- CVE-2019-144711 PoCTestLink 1.9.19 has XSS via the error.php message parameter.
- CVE-2019-144721 PoCZurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
- CVE-2019-144781 PoCAdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is…
- CVE-2019-144811 PoCAdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation…
- CVE-2019-144921 PoCAn issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function…
- CVE-2019-144941 PoCAn issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at…
- CVE-2019-145131 PoCImproper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read…
- CVE-2019-145141 PoCAn issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains…
- CVE-2019-145171 PoCpandao Editor.md 1.5.0 allows XSS via the Javascript: string.
- CVE-2019-145181 PoCEvolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is…
- CVE-2019-145291 PoCOpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
- CVE-2019-145308 PoCsAn issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file…
- CVE-2019-145311 PoCAn issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol…
- CVE-2019-145321 PoCAn issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp…
- CVE-2019-145371 PoCYOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
- CVE-2019-145401 PoCA Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
- CVE-2019-145461 PoCAn issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a…
- CVE-2019-145471 PoCAn issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin with malicious…
- CVE-2019-145481 PoCAn issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens articles received…
- CVE-2019-145491 PoCAn issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly formed entity…
- CVE-2019-145501 PoCAn issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feature present on the…
- CVE-2019-145511 PoCDas Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request…
- CVE-2019-146562 PoCsYealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a…
- CVE-2019-146572 PoCsYealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate…
- CVE-2019-146641 PoCIn Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The…
- CVE-2019-146662 PoCsGLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct…
- CVE-2019-146671 PoCFirefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction…
- CVE-2019-146681 PoCFirefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field.…
- CVE-2019-146691 PoCFirefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The…
- CVE-2019-146701 PoCFirefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The…
- CVE-2019-146782 PoCsSAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples…
- CVE-2019-146791 PoCcore/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
- CVE-2019-146801 PoCThe admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows…
- CVE-2019-146811 PoCThe Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.
- CVE-2019-146821 PoCThe acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page…
- CVE-2019-146831 PoCThe codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows…
- CVE-2019-146841 PoCA DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an…
- CVE-2019-146941 PoCA use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race…
- CVE-2019-146963 PoCsOpen-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
- CVE-2019-147151 PoCVerifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.
- CVE-2019-147371 PoCUbisoft Uplay 92.0.0.6280 has Insecure Permissions.
- CVE-2019-147432 PoCsIn Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users…
- CVE-2019-147452 PoCsIn radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable…
- CVE-2019-147471 PoCDWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
- CVE-2019-147482 PoCsAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along…
- CVE-2019-147491 PoCAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets…
- CVE-2019-147502 PoCsAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that…
- CVE-2019-147512 PoCsNLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash)…
- CVE-2019-147561 PoCAn issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript…
- CVE-2019-147721 PoCverdaccio before 3.12.0 allows XSS.
- CVE-2019-147731 PoCadmin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows…
- CVE-2019-147741 PoCThe woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the…
- CVE-2019-147821 PoCCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the…
- CVE-2019-147851 PoCThe "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the…
- CVE-2019-147862 PoCsThe Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb…
- CVE-2019-147872 PoCsThe Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor…
- CVE-2019-147881 PoCwp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory…
- CVE-2019-147892 PoCsThe Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
- CVE-2019-147901 PoCThe limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the…
- CVE-2019-147911 PoCThe Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
- CVE-2019-147921 PoCThe WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
- CVE-2019-147931 PoCThe Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file…
- CVE-2019-147951 PoCThe toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options…
- CVE-2019-147961 PoCThe mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows XSS via the…
- CVE-2019-147981 PoCThe 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversal in the…
- CVE-2019-147992 PoCsThe FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
- CVE-2019-148001 PoCThe FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format…
- CVE-2019-148041 PoCstudio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template editing.
- CVE-2019-148111 PoCA flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its…
- CVE-2019-148621 PoCThere is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web…
- CVE-2019-149122 PoCsAn issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect…
- CVE-2019-149131 PoCAn issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the administration panel.
- CVE-2019-149161 PoCAn issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file upload.
- CVE-2019-149231 PoCEyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
- CVE-2019-149251 PoCAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A…
- CVE-2019-149261 PoCAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH…
- CVE-2019-149272 PoCsAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An…
- CVE-2019-149281 PoCAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of…
- CVE-2019-149291 PoCAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored…
- CVE-2019-149301 PoCAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented…
- CVE-2019-149312 PoCsAn issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An…
- CVE-2019-149351 PoC3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing…
- CVE-2019-149451 PoCThe ultimate-member plugin before 2.0.54 for WordPress has XSS.
- CVE-2019-149461 PoCThe ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
- CVE-2019-149471 PoCThe ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
- CVE-2019-149481 PoCThe woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
- CVE-2019-149501 PoCThe wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
- CVE-2019-149743 PoCsSugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
- CVE-2019-149781 PoC/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the…
- CVE-2019-149791 PoCcgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an…
- CVE-2019-149821 PoCIn Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can…
- CVE-2019-149952 PoCsThe /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a…
- CVE-2019-149981 PoCThe Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to…