Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15128 1 If.svnadmin Project 1 If.svnadmin 2019-09-09 4.3 MEDIUM 6.5 MEDIUM
iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.
CVE-2017-18559 1 Cformsii Project 1 Cformsii 2019-09-08 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
CVE-2017-18499 1 Simple-membership-plugin 1 Simple Membership 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The simple-membership plugin before 3.5.7 for WordPress has XSS.
CVE-2018-17585 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
CVE-2018-17583 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
CVE-2018-17586 1 Wpfastestcache 1 Wp Fastest Cache 2019-09-07 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
CVE-2019-2103 1 Google 1 Android 2019-09-06 2.1 LOW 5.5 MEDIUM
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-10753 1 Diffplug 3 Eclipse-cdt, Eclipse-groovy, Eclipse-wtp 2019-09-06 4.3 MEDIUM 5.9 MEDIUM
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts that were produced. In case that any of these artifacts were compromised, any developers using these could be altered. **Note:** In order to validate that this artifact was not compromised, the maintainer would need to confirm that none of the artifacts published to the registry were not altered with. Until this happens, we can not guarantee that this artifact was not compromised even though the probability that this happened is low.
CVE-2019-13190 1 Eng 1 Knowage 2019-09-06 5.0 MEDIUM 5.3 MEDIUM
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
CVE-2019-13209 1 Rancher 1 Rancher 2019-09-06 4.3 MEDIUM 6.1 MEDIUM
Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access to clusters managed by Rancher. The attack requires a victim to be logged into a Rancher server, and then to access a third-party site hosted by the exploiter. Once that is accomplished, the exploiter is able to execute commands against the cluster's Kubernetes API with the permissions and identity of the victim.
CVE-2019-10140 2 Linux, Redhat 2 Linux Kernel, Enterprise Linux 2019-09-06 4.9 MEDIUM 5.5 MEDIUM
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
CVE-2019-15291 1 Linux 1 Linux Kernel 2019-09-06 4.9 MEDIUM 4.6 MEDIUM
An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-1020010 1 Misskey 1 Misskey 2019-09-05 4.3 MEDIUM 6.1 MEDIUM
Misskey before 10.102.4 allows hijacking a user's token.
CVE-2019-15818 1 Webcraftic 1 Simple 301 Redirects 2019-09-05 5.8 MEDIUM 6.1 MEDIUM
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
CVE-2019-14470 2 Instagram-php-api Project, Userproplugin 2 Instagram-php-api, User Pro 2019-09-05 4.3 MEDIUM 6.1 MEDIUM
cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has XSS via the example/success.php error_description parameter.
CVE-2019-15820 1 Login Or Logout Menu Item Project 1 Login Or Logout Menu Item 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
CVE-2019-15714 1 Entropic Project 1 Entropic 2019-09-04 5.0 MEDIUM 5.3 MEDIUM
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
CVE-2019-15814 1 Sentrifugo 1 Sentrifugo 2019-09-04 3.5 LOW 5.4 MEDIUM
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
CVE-2018-20977 1 Brainstormforce 1 Schema 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-schemaorg-rich-snippets plugin before 1.5.0 for WordPress has XSS on the settings page.
CVE-2019-15109 1 Tri 1 The Events Calendar 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
CVE-2016-10892 1 Kibokolabs 1 Chained Quiz 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
CVE-2019-15771 1 Components For Wp Bakery Page Builder Project 1 Components For Wp Bakery Page Builder 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-15889 1 Wpdownloadmanager 1 Wordpress Download Manager 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
CVE-2019-15898 1 Nagios 1 Log Server 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
CVE-2019-15776 1 Webcraftic 1 Simple 301 Redirects-addon-bulk Uploader 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
CVE-2019-15773 1 Travel Management Project 1 Travel Management 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-15772 1 Donations Project 1 Donations 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2015-9369 1 Ithemes 1 Easy Us Sales Taxes 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15836 1 Bootstrapped 1 Wp Ultimate Recipe 2019-09-04 3.5 LOW 5.4 MEDIUM
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CVE-2019-15700 1 Frappe 1 Frappe 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
CVE-2015-9375 1 Ithemes 1 Table Rate Shipping 2019-09-04 4.3 MEDIUM 6.1 MEDIUM
Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15774 1 Booking Project 1 Booking 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-15775 1 Learning Courses Project 1 Learning Courses 2019-09-04 5.8 MEDIUM 6.1 MEDIUM
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2015-9373 1 Webdevstudios 1 Ithemes Paypal Pro 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9366 1 Ithemes 1 Custom Url Tracking 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9370 1 Ithemes 1 Invoices 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9371 1 Ithemes 1 Manual Purchases 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9372 1 Ithemes 1 Membership 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15837 1 Bitwise-it 1 Webp Express 2019-09-03 3.5 LOW 5.4 MEDIUM
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15777 1 Shapepress 1 Wp Dsgvo Tools 2019-09-03 3.5 LOW 5.4 MEDIUM
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
CVE-2015-9374 1 Ithemes 1 Stripe 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15829 1 Greentreelabs 1 Gallery Photoblocks 2019-09-03 3.5 LOW 4.8 MEDIUM
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
CVE-2019-15827 1 Onesignal 1 Onesignal-free-web-push-notifications 2019-09-03 3.5 LOW 5.4 MEDIUM
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
CVE-2018-15510 1 Totemo 1 Totemomail 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2019-12754 1 Symantec 1 Vip 2019-09-03 3.5 LOW 4.8 MEDIUM
Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users or potentially bypass access controls such as the same-origin policy.
CVE-2018-15511 1 Totemo 1 Totemomail 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2018-15513 1 Totemo 1 Totemomail 2019-09-03 5.0 MEDIUM 5.3 MEDIUM
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
CVE-2019-15864 1 Holest 1 Breadcrumbs By Menu 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
CVE-2018-15512 1 Totemo 1 Totemomail 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
CVE-2019-15870 1 Carspot Project 1 Carspot 2019-09-03 3.5 LOW 5.4 MEDIUM
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.