|
250341
|
6.1 |
MEDIUM
Network
|
pinfinity_project
|
pinfinity
|
The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18599
|
2024-11-21 12:20 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250342
|
6.1 |
MEDIUM
Network
|
designmodo
|
qards
|
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18598
|
2024-11-21 12:20 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250343
|
8.8 |
HIGH
Network
|
jtrt_responsive_tables_project
|
jtrt_responsive_tables
|
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18597
|
2024-11-21 12:20 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250344
|
8.8 |
HIGH
Network
|
elementor
|
elementor_page_builder
|
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
|
CWE-269
Improper Privilege Management
|
CVE-2017-18596
|
2024-11-21 12:20 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250345
|
7.8 |
HIGH
Local
|
linux opensuse
|
linux_kernel leap
|
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.
|
CWE-415
Double Free
|
CVE-2017-18595
|
2024-11-21 12:20 |
2019-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250346
|
7.5 |
HIGH
Network
|
nmap
|
nmap
|
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-metho…
|
CWE-415
Double Free
|
CVE-2017-18594
|
2024-11-21 12:20 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250347
|
6.1 |
MEDIUM
Network
|
updraftplus
|
updraftplus
|
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18593
|
2024-11-21 12:20 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250348
|
7.5 |
HIGH
Network
|
wc-marketplace
|
wc_catalog_enquiry
|
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-18592
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250349
|
6.1 |
MEDIUM
Network
|
gdragon
|
gd_rating_system
|
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18591
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250350
|
6.1 |
MEDIUM
Network
|
bestwebsoft
|
timesheet
|
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18590
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|