Show filters
733 Total Results
Displaying 311-320 of 733
Sort by:
Attacker Value
Unknown
CVE-2015-9306
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-1010290
Disclosure Date: July 16, 2019 (last updated November 27, 2024)
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.
0
Attacker Value
Unknown
CVE-2019-12813
Disclosure Date: June 13, 2019 (last updated November 27, 2024)
An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating the fingerprint image exhibit cleartext when the fingerprint scanner device transfers a fingerprint image to the driver. An attacker who sniffs an encrypted fingerprint image can easily decrypt that image using the key and salt.
0
Attacker Value
Unknown
CVE-2019-11226
Disclosure Date: June 05, 2019 (last updated November 27, 2024)
CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
0
Attacker Value
Unknown
CVE-2018-20580
Disclosure Date: May 03, 2019 (last updated November 27, 2024)
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
0
Attacker Value
Unknown
CVE-2019-11513
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action.
0
Attacker Value
Unknown
CVE-2019-11506
Disclosure Date: April 24, 2019 (last updated November 27, 2024)
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
0
Attacker Value
Unknown
CVE-2019-11505
Disclosure Date: April 24, 2019 (last updated November 27, 2024)
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c.
0
Attacker Value
Unknown
CVE-2019-7213
Disclosure Date: April 24, 2019 (last updated November 27, 2024)
SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could create files in new folders in arbitrary locations on the mail server. This could lead to command execution on the server for instance by putting files inside the web directories.
0
Attacker Value
Unknown
CVE-2019-7214
Disclosure Date: April 24, 2019 (last updated November 27, 2024)
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.
0