Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15559 1 Hawn Project 1 Hawn 2019-08-29 7.5 HIGH 9.8 CRITICAL
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVE-2019-15224 1 Rest-client Project 1 Rest-client 2019-08-29 7.5 HIGH 9.8 CRITICAL
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
CVE-2018-16255 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2018-16256 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2018-16257 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2018-16258 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2018-16259 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2019-8447 1 Atlassian 1 Jira 2019-08-29 4.3 MEDIUM 4.3 MEDIUM
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
CVE-2019-15563 1 Ohdsi 1 Webapi 2019-08-29 7.5 HIGH 9.8 CRITICAL
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.
CVE-2019-15570 1 Bedita 1 Bedita 2019-08-29 7.5 HIGH 9.8 CRITICAL
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2015-9357 1 Automattic 1 Akismet 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The akismet plugin before 3.1.5 for WordPress has XSS.
CVE-2019-13189 1 Eng 1 Knowage 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
CVE-2019-9930 1 Lexmark 142 6500e, 6500e Firmware, C734 and 139 more 2019-08-29 10.0 HIGH 9.8 CRITICAL
Various Lexmark products have an Integer Overflow.
CVE-2018-16254 1 Soflyy 1 Wp All Import 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator.
CVE-2019-9150 1 Mailvelope 1 Mailvelope 2019-08-29 5.0 MEDIUM 5.3 MEDIUM
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key was imported.
CVE-2019-10057 1 Lexmark 50 Cs31x, Cs31x Firmware, Cs41x and 47 more 2019-08-29 4.3 MEDIUM 6.5 MEDIUM
Various Lexmark products have CSRF.
CVE-2019-15536 1 Youracclaim 1 Acclaim 2019-08-29 7.5 HIGH 9.8 CRITICAL
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
CVE-2019-15546 1 Pancurses Project 1 Pancurses 2019-08-29 6.4 MEDIUM 7.5 HIGH
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.
CVE-2015-9348 1 Codepeople 1 Sell Downloads 2019-08-29 5.0 MEDIUM 7.5 HIGH
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
CVE-2018-14668 1 Yandex 1 Clickhouse 2019-08-29 6.8 MEDIUM 8.8 HIGH
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
CVE-2019-15547 1 Ncurses Project 1 Ncurses 2019-08-29 6.4 MEDIUM 7.5 HIGH
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
CVE-2017-18592 1 Wc-marketplace 1 Wc Catalog Enquiry 2019-08-29 5.0 MEDIUM 7.5 HIGH
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
CVE-2019-15548 1 Ncurses Project 1 Ncurses 2019-08-29 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
CVE-2012-3006 1 Innominate 19 Eagle Mguard Bd-301010, Eagle Mguard Hw-201000, Mguard Blade Hw-104020 and 16 more 2019-08-29 7.1 HIGH N/A
The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value.
CVE-2017-18591 1 Gdragon 1 Gd Rating System 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
CVE-2019-15133 2 Canonical, Giflib Project 2 Ubuntu Linux, Giflib 2019-08-29 4.3 MEDIUM 6.5 MEDIUM
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero.
CVE-2015-9343 1 Impress 1 Wp Rollback 2019-08-29 6.8 MEDIUM 8.8 HIGH
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
CVE-2018-18668 1 Gnuboard 1 Gnuboard5 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter.
CVE-2019-15647 1 Groundhogg 1 Groundhogg 2019-08-29 6.5 MEDIUM 8.8 HIGH
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
CVE-2018-18572 1 Oscommerce 1 Oscommerce 2019-08-29 6.5 MEDIUM 7.2 HIGH
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
CVE-2015-9354 1 Tri.be 1 Gigpress 2019-08-29 3.5 LOW 4.8 MEDIUM
The gigpress plugin before 2.3.11 for WordPress has XSS.
CVE-2016-10928 1 Onelogin 1 Onelogin Saml Sso 2019-08-29 5.0 MEDIUM 7.5 HIGH
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
CVE-2017-18579 1 Dwbooster 1 Corner Ad 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The corner-ad plugin before 1.0.8 for WordPress has XSS.
CVE-2015-9338 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9339 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9340 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
CVE-2016-10934 1 Check Email Project 1 Check Email 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The check-email plugin before 0.5.2 for WordPress has XSS.
CVE-2014-10382 1 Pippinsplugins 1 Featured Comments 2019-08-29 4.3 MEDIUM 4.3 MEDIUM
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
CVE-2014-10386 1 Wp-livechat 1 Wp Live Chat Support 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
CVE-2015-9334 1 Email-newsletter Project 1 Email-newsletter 2019-08-29 7.5 HIGH 9.8 CRITICAL
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
CVE-2013-7483 1 Hbwsl 1 Slidedeck 2 2019-08-29 7.5 HIGH 9.8 CRITICAL
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
CVE-2017-18586 1 Insert Pages Project 1 Insert Pages 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.
CVE-2016-10930 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
CVE-2015-9341 1 Iptanus 1 Wordpress File Upload 2019-08-29 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2014-10394 1 Saschart 1 Rich Counter 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10390 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 6.4 MEDIUM 9.1 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVE-2014-10391 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10389 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
CVE-2014-10388 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 5.0 MEDIUM 5.3 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVE-2018-1129 4 Ceph, Debian, Opensuse and 1 more 10 Ceph, Debian Linux, Leap and 7 more 2019-08-29 3.3 LOW 6.5 MEDIUM
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.