Search
Total
201818 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-15559 | 1 Hawn Project | 1 Hawn | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| DianoxDragon Hawn before 2019-07-10 allows SQL injection. | |||||
| CVE-2019-15224 | 1 Rest-client Project | 1 Rest-client | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected. | |||||
| CVE-2018-16255 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2018-16256 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2018-16257 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2018-16258 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2018-16259 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2019-8447 | 1 Atlassian | 1 Jira | 2019-08-29 | 4.3 MEDIUM | 4.3 MEDIUM |
| The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability. | |||||
| CVE-2019-15563 | 1 Ohdsi | 1 Webapi | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java. | |||||
| CVE-2019-15570 | 1 Bedita | 1 Bedita | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. | |||||
| CVE-2015-9357 | 1 Automattic | 1 Akismet | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The akismet plugin before 3.1.5 for WordPress has XSS. | |||||
| CVE-2019-13189 | 1 Eng | 1 Knowage | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page. | |||||
| CVE-2019-9930 | 1 Lexmark | 142 6500e, 6500e Firmware, C734 and 139 more | 2019-08-29 | 10.0 HIGH | 9.8 CRITICAL |
| Various Lexmark products have an Integer Overflow. | |||||
| CVE-2018-16254 | 1 Soflyy | 1 Wp All Import | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator. | |||||
| CVE-2019-9150 | 1 Mailvelope | 1 Mailvelope | 2019-08-29 | 5.0 MEDIUM | 5.3 MEDIUM |
| Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can be tricked to either hide a key import from the user or obscure which key was imported. | |||||
| CVE-2019-10057 | 1 Lexmark | 50 Cs31x, Cs31x Firmware, Cs41x and 47 more | 2019-08-29 | 4.3 MEDIUM | 6.5 MEDIUM |
| Various Lexmark products have CSRF. | |||||
| CVE-2019-15536 | 1 Youracclaim | 1 Acclaim | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. | |||||
| CVE-2019-15546 | 1 Pancurses Project | 1 Pancurses | 2019-08-29 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities. | |||||
| CVE-2015-9348 | 1 Codepeople | 1 Sell Downloads | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs. | |||||
| CVE-2018-14668 | 1 Yandex | 1 Clickhouse | 2019-08-29 | 6.8 MEDIUM | 8.8 HIGH |
| In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks. | |||||
| CVE-2019-15547 | 1 Ncurses Project | 1 Ncurses | 2019-08-29 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled. | |||||
| CVE-2017-18592 | 1 Wc-marketplace | 1 Wc Catalog Enquiry | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads. | |||||
| CVE-2019-15548 | 1 Ncurses Project | 1 Ncurses | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. | |||||
| CVE-2012-3006 | 1 Innominate | 19 Eagle Mguard Bd-301010, Eagle Mguard Hw-201000, Mguard Blade Hw-104020 and 16 more | 2019-08-29 | 7.1 HIGH | N/A |
| The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value. | |||||
| CVE-2017-18591 | 1 Gdragon | 1 Gd Rating System | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php. | |||||
| CVE-2019-15133 | 2 Canonical, Giflib Project | 2 Ubuntu Linux, Giflib | 2019-08-29 | 4.3 MEDIUM | 6.5 MEDIUM |
| In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero. | |||||
| CVE-2015-9343 | 1 Impress | 1 Wp Rollback | 2019-08-29 | 6.8 MEDIUM | 8.8 HIGH |
| The wp-rollback plugin before 1.2.3 for WordPress has CSRF. | |||||
| CVE-2018-18668 | 1 Gnuboard | 1 Gnuboard5 | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter. | |||||
| CVE-2019-15647 | 1 Groundhogg | 1 Groundhogg | 2019-08-29 | 6.5 MEDIUM | 8.8 HIGH |
| The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution. | |||||
| CVE-2018-18572 | 1 Oscommerce | 1 Oscommerce | 2019-08-29 | 6.5 MEDIUM | 7.2 HIGH |
| osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI. | |||||
| CVE-2015-9354 | 1 Tri.be | 1 Gigpress | 2019-08-29 | 3.5 LOW | 4.8 MEDIUM |
| The gigpress plugin before 2.3.11 for WordPress has XSS. | |||||
| CVE-2016-10928 | 1 Onelogin | 1 Onelogin Saml Sso | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users. | |||||
| CVE-2017-18579 | 1 Dwbooster | 1 Corner Ad | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The corner-ad plugin before 1.0.8 for WordPress has XSS. | |||||
| CVE-2015-9338 | 1 Iptanus | 1 Wordpress File Upload | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. | |||||
| CVE-2015-9339 | 1 Iptanus | 1 Wordpress File Upload | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. | |||||
| CVE-2015-9340 | 1 Iptanus | 1 Wordpress File Upload | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files. | |||||
| CVE-2016-10934 | 1 Check Email Project | 1 Check Email | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The check-email plugin before 0.5.2 for WordPress has XSS. | |||||
| CVE-2014-10382 | 1 Pippinsplugins | 1 Featured Comments | 2019-08-29 | 4.3 MEDIUM | 4.3 MEDIUM |
| The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. | |||||
| CVE-2014-10386 | 1 Wp-livechat | 1 Wp Live Chat Support | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | |||||
| CVE-2015-9334 | 1 Email-newsletter Project | 1 Email-newsletter | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The email-newsletter plugin through 20.15 for WordPress has SQL injection. | |||||
| CVE-2013-7483 | 1 Hbwsl | 1 Slidedeck 2 | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion. | |||||
| CVE-2017-18586 | 1 Insert Pages Project | 1 Insert Pages | 2019-08-29 | 6.4 MEDIUM | 9.1 CRITICAL |
| The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. | |||||
| CVE-2016-10930 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | |||||
| CVE-2015-9341 | 1 Iptanus | 1 Wordpress File Upload | 2019-08-29 | 5.0 MEDIUM | 7.5 HIGH |
| The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. | |||||
| CVE-2014-10394 | 1 Saschart | 1 Rich Counter | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. | |||||
| CVE-2014-10390 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 6.4 MEDIUM | 9.1 CRITICAL |
| The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | |||||
| CVE-2014-10391 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | |||||
| CVE-2014-10389 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 7.5 HIGH | 9.8 CRITICAL |
| The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | |||||
| CVE-2014-10388 | 1 Wpsupportplus | 1 Wp Support Plus Responsive Ticket System | 2019-08-29 | 5.0 MEDIUM | 5.3 MEDIUM |
| The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. | |||||
| CVE-2018-1129 | 4 Ceph, Debian, Opensuse and 1 more | 10 Ceph, Debian Linux, Leap and 7 more | 2019-08-29 | 3.3 LOW | 6.5 MEDIUM |
| A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. | |||||
