Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20998 1 Arrayfire 1 Arrayfire 2019-08-30 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.
CVE-2019-15149 1 Networkgenomics 1 Mitogen 2019-08-30 6.8 MEDIUM 9.8 CRITICAL
** DISPUTED ** core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.
CVE-2018-14671 1 Yandex 1 Clickhouse 2019-08-29 7.5 HIGH 9.8 CRITICAL
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability.
CVE-2019-15559 1 Hawn Project 1 Hawn 2019-08-29 7.5 HIGH 9.8 CRITICAL
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVE-2019-15224 1 Rest-client Project 1 Rest-client 2019-08-29 7.5 HIGH 9.8 CRITICAL
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
CVE-2019-15563 1 Ohdsi 1 Webapi 2019-08-29 7.5 HIGH 9.8 CRITICAL
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.
CVE-2019-15570 1 Bedita 1 Bedita 2019-08-29 7.5 HIGH 9.8 CRITICAL
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-9930 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2019-08-29 10.0 HIGH 9.8 CRITICAL
Various Lexmark products have an Integer Overflow.
CVE-2019-15536 1 Youracclaim 1 Acclaim 2019-08-29 7.5 HIGH 9.8 CRITICAL
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
CVE-2019-15548 1 Ncurses Project 1 Ncurses 2019-08-29 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
CVE-2015-9334 1 Email-newsletter Project 1 Email-newsletter 2019-08-29 7.5 HIGH 9.8 CRITICAL
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVE-2017-18586 1 Insert Pages Project 1 Insert Pages 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
CVE-2013-7483 1 Hbwsl 1 Slidedeck 2 2019-08-29 7.5 HIGH 9.8 CRITICAL
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
CVE-2016-10930 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
CVE-2014-10390 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVE-2014-10389 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
CVE-2012-6719 1 Sharebar Project 1 Sharebar 2019-08-28 7.5 HIGH 9.8 CRITICAL
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2018-14062 1 Cospas-sarsat 1 Cospas-sarsat System 2019-08-28 9.4 HIGH 9.1 CRITICAL
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.
CVE-2019-15568 1 Idseq 1 Idseq-web 2019-08-28 7.5 HIGH 9.8 CRITICAL
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2019-15659 1 Genetechsolutions 1 Pie Register 2019-08-28 7.5 HIGH 9.8 CRITICAL
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2015-9351 1 Slickremix 1 Feed Them Social 2019-08-28 7.5 HIGH 9.8 CRITICAL
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
CVE-2015-9352 1 Wp-polls Project 1 Wp-polls 2019-08-28 7.5 HIGH 9.8 CRITICAL
The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2019-15646 1 Rsvpmaker Project 1 Rsvpmaker 2019-08-28 7.5 HIGH 9.8 CRITICAL
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
CVE-2018-21004 1 Rsvpmaker Project 1 Rsvpmaker 2019-08-28 7.5 HIGH 9.8 CRITICAL
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
CVE-2019-15537 1 Cesnet 1 Proxystatistics 2019-08-28 7.5 HIGH 9.8 CRITICAL
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2019-15565 1 Webimpacto 1 Icommktconnector 2019-08-28 7.5 HIGH 9.8 CRITICAL
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
CVE-2019-15567 1 Openforis 1 Arena 2019-08-28 7.5 HIGH 9.8 CRITICAL
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2019-13452 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CVE-2019-13451 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CVE-2019-13484 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of &nbsp; expansion in appfeed.c.
CVE-2018-14670 1 Yandex 1 Clickhouse 2019-08-28 7.5 HIGH 9.8 CRITICAL
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2018-21003 1 Themekraft 1 Buddyforms 2019-08-28 7.5 HIGH 9.8 CRITICAL
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2019-15521 2 Fork-cms, Spoon-library 2 Fork Cms, Spoon Library 2019-08-28 7.5 HIGH 9.8 CRITICAL
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
CVE-2019-15556 1 Social Network Project 1 Social Network 2019-08-28 7.5 HIGH 9.8 CRITICAL
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
CVE-2019-15561 1 Flashlingo Project 1 Flashlingo 2019-08-28 7.5 HIGH 9.8 CRITICAL
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
CVE-2019-14234 3 Debian, Djangoproject, Fedoraproject 3 Debian Linux, Django, Fedora 2019-08-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.
CVE-2019-15566 1 Alfresco 1 Alfresco 2019-08-27 7.5 HIGH 9.8 CRITICAL
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
CVE-2019-15564 1 Compassionuk 1 Compassion Switzerland 2019-08-27 7.5 HIGH 9.8 CRITICAL
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
CVE-2019-14527 1 Netgear 2 Mr1100, Mr1100 Firmware 2019-08-27 10.0 HIGH 9.8 CRITICAL
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.
CVE-2019-10687 1 Kbpublisher 1 Kbpublisher 2019-08-27 7.5 HIGH 9.8 CRITICAL
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-15091 1 Artica 1 Integria Ims 2019-08-27 7.5 HIGH 9.8 CRITICAL
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
CVE-2018-20961 1 Linux 1 Linux Kernel 2019-08-27 10.0 HIGH 9.8 CRITICAL
In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2019-15494 1 It-novum 1 Openitcockpit 2019-08-26 7.5 HIGH 9.8 CRITICAL
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
CVE-2019-15535 1 Hostosm 1 Tasking Manager 2019-08-26 7.5 HIGH 9.8 CRITICAL
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
CVE-2016-10922 1 Visser 1 Store Toolkit For Woocommerce 2019-08-26 7.5 HIGH 9.8 CRITICAL
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2014-10384 1 Memphis Documents Library Project 1 Memphis Documents Library 2019-08-26 7.5 HIGH 9.8 CRITICAL
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
CVE-2014-10383 1 Memphis Documents Library Project 1 Memphis Documents Library 2019-08-26 7.5 HIGH 9.8 CRITICAL
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
CVE-2014-10387 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-26 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
CVE-2019-15534 1 Raml-module-builder Project 1 Raml-module-builder 2019-08-26 7.5 HIGH 9.8 CRITICAL
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2018-20981 1 Ninjaforms 1 Ninja Forms 2019-08-26 6.4 MEDIUM 9.1 CRITICAL
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.