Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15869 1 Jobcareer Project 1 Jobcareer 2019-09-03 3.5 LOW 5.4 MEDIUM
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
CVE-2015-9367 1 Ithemes 1 Easy Canadian Sales Taxes 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9368 1 Ithemes 1 Easy Eu Value Added \(vat\) Taxes 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-5590 1 Fortinet 1 Fortiweb 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form.
CVE-2019-15838 1 Custom 404 Pro Project 1 Custom 404 Pro 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2015-9358 1 Feedwordpress Project 1 Feedwordpress 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15817 1 Realestateconnected 1 Easy Property Listings 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The easy-property-listings plugin before 3.4 for WordPress has XSS.
CVE-2019-10059 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2019-09-03 5.0 MEDIUM 5.3 MEDIUM
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
CVE-2017-18587 1 Hyper 1 Hyper 2019-09-03 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.
CVE-2015-9378 1 Ithemes 1 Builder Theme Market 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
iThemes Builder Theme Market before 5.1.27 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9355 1 Simbahosting 1 Two-factor-authentication 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
CVE-2015-9379 1 Ithemes 1 Builder Style Manager 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
iThemes Builder Style Manager before 0.7.7 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9377 1 Ithemes 1 Builder Theme Depot 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
iThemes Builder Theme Depot before 5.0.30 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15811 1 Domainmod 1 Domainmod 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
CVE-2019-15842 1 Easy Pdf Restaurant Menu Upload Project 1 Easy Pdf Restaurant Menu Upload 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15778 1 Getwooplugins 1 Additional Variation Images For Woocommerce 2019-09-03 3.5 LOW 5.4 MEDIUM
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
CVE-2018-16967 1 File Manager Project 1 File Manager 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
CVE-2018-17866 1 Ultimatemember 1 Ultimate Member 2019-09-03 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
CVE-2019-3701 3 Canonical, Debian, Linux 3 Ubuntu Linux, Debian Linux, Linux Kernel 2019-09-03 4.9 MEDIUM 4.4 MEDIUM
An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the available CAN frame data size. In combination with a configured checksum calculation where the result is stored relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb (e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can cause a system crash. Because of a missing check, the CAN drivers may write arbitrary content beyond the data registers in the CAN controller's I/O memory when processing can-gw manipulated outgoing frames.
CVE-2018-19985 3 Debian, Linux, Netapp 4 Debian Linux, Linux Kernel, Active Iq Performance Analytics Services and 1 more 2019-09-03 2.1 LOW 4.6 MEDIUM
The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.
CVE-2019-15081 1 Opencart 1 Opencart 2019-09-02 3.5 LOW 4.8 MEDIUM
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing feature of the Categories, Product, and Information pages.
CVE-2019-13235 1 Alkacon 1 Opencms Apollo Template 2019-09-02 4.3 MEDIUM 6.1 MEDIUM
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
CVE-2019-13234 1 Alkacon 1 Opencms Apollo Template 2019-09-02 4.3 MEDIUM 6.1 MEDIUM
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
CVE-2019-13236 1 Alkacon 1 Opencms 2019-09-02 4.3 MEDIUM 6.1 MEDIUM
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the management interface.
CVE-2019-14280 1 Craftcms 1 Craft Cms 2019-09-02 5.0 MEDIUM 5.3 MEDIUM
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
CVE-2016-10872 1 Ultimatemember 1 Ultimate Member 2019-09-02 4.3 MEDIUM 6.1 MEDIUM
The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2016-10875 1 Wpseeds 1 Wp Database Backup 2019-09-01 4.3 MEDIUM 6.1 MEDIUM
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
CVE-2011-5329 1 Redirection 1 Redirection 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
CVE-2012-6717 1 Redirection 1 Redirection 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
CVE-2015-9359 1 Automattic 1 Jetpack 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The Jetpack plugin before 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9360 1 Updraftplus 1 Updraftplus 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2017-18593 1 Updraftplus 1 Updraftplus 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
CVE-2019-11658 1 Microfocus 1 Content Manager 2019-08-30 4.0 MEDIUM 4.3 MEDIUM
Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to use an Oracle database, allows valid system users to gain access to a limited subset of records they would not normally be able to access when the system is in an undisclosed abnormal state.
CVE-2019-15641 1 Webmin 1 Webmin 2019-08-30 6.8 MEDIUM 6.5 MEDIUM
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
CVE-2015-9356 1 Wp-vipergb Project 1 Wp-vipergb 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue than CVE-2014-9460.
CVE-2019-15230 1 Librenms 1 Librenms 2019-08-30 3.5 LOW 5.4 MEDIUM
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.
CVE-2015-9364 1 2checkout 1 Ithemes 2checkout 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9362 1 Never5 1 Post Connector 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9363 1 Ithemes 1 Exchange 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9365 1 Ithemes 1 Authorize.net 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2015-9361 1 Never5 1 Related Posts 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-1010124 1 Webappick 1 Woocommerce Product Feed 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.
CVE-2019-11589 1 Atlassian 1 Jira 2019-08-30 5.8 MEDIUM 6.1 MEDIUM
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability.
CVE-2017-18588 1 Security-framework Project 1 Security-framework 2019-08-30 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
CVE-2019-14999 1 Atlassian 1 Universal Plugin Manager 2019-08-30 4.3 MEDIUM 4.3 MEDIUM
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
CVE-2019-15045 1 Zohocorp 1 Manageengine Servicedesk Plus 2019-08-30 5.0 MEDIUM 5.3 MEDIUM
** DISPUTED ** AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality.
CVE-2019-14774 1 Getwooplugins 1 Woo-variation-swatches 2019-08-30 4.3 MEDIUM 6.1 MEDIUM
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
CVE-2019-13564 1 Pingidentity 1 Agentless Integration Kit 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Ping Identity Agentless Integration Kit before 1.5.
CVE-2015-9376 1 Ithemes 1 Mobile 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
iThemes Mobile before 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
CVE-2019-15515 1 Discourse 1 Discourse 2019-08-29 4.3 MEDIUM 6.5 MEDIUM
Discourse 2.3.2 sends the CSRF token in the query string.