Show filters
733 Total Results
Displaying 311-320 of 733
Sort by:
Attacker Value
Unknown

CVE-2015-9306

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2019-1010290

Disclosure Date: July 16, 2019 (last updated November 27, 2024)
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.
0
Attacker Value
Unknown

CVE-2019-12813

Disclosure Date: June 13, 2019 (last updated November 27, 2024)
An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.
0
Attacker Value
Unknown

CVE-2019-11226

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
0
Attacker Value
Unknown

CVE-2018-20580

Disclosure Date: May 03, 2019 (last updated November 27, 2024)
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
0
Attacker Value
Unknown

CVE-2019-11513

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
0
Attacker Value
Unknown

CVE-2019-11506

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
Attacker Value
Unknown

CVE-2019-11505

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
Attacker Value
Unknown

CVE-2019-7213

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by putting files inside the web directories.
0
Attacker Value
Unknown

CVE-2019-7214

Disclosure Date: April 24, 2019 (last updated November 27, 2024)
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
0