Search
Total
201818 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-21002 | 1 Joomsky | 1 Js Help Desk | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
| The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | |||||
| CVE-2012-6718 | 1 Sharebar Project | 1 Sharebar | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491. | |||||
| CVE-2012-6719 | 1 Sharebar Project | 1 Sharebar | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The sharebar plugin before 1.2.2 for WordPress has SQL injection. | |||||
| CVE-2018-14062 | 1 Cospas-sarsat | 1 Cospas-sarsat System | 2019-08-28 | 9.4 HIGH | 9.1 CRITICAL |
| The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal. | |||||
| CVE-2019-15568 | 1 Idseq | 1 Idseq-web | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. | |||||
| CVE-2018-18573 | 1 Oscommerce | 1 Oscommerce | 2019-08-28 | 6.5 MEDIUM | 7.2 HIGH |
| osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI. | |||||
| CVE-2014-10395 | 1 Codepeople | 1 Polls Cp | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. | |||||
| CVE-2015-9342 | 1 Impress | 1 Wp Rollback | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-rollback plugin before 1.2.3 for WordPress has XSS. | |||||
| CVE-2019-15659 | 1 Genetechsolutions | 1 Pie Register | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. | |||||
| CVE-2015-9349 | 1 Cksource | 1 Ckeditor | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser. | |||||
| CVE-2019-15660 | 1 Wp-members Project | 1 Wp-members | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
| The wp-members plugin before 3.2.8 for WordPress has CSRF. | |||||
| CVE-2015-9351 | 1 Slickremix | 1 Feed Them Social | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button. | |||||
| CVE-2015-9350 | 1 Slickremix | 1 Feed Them Social | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button. | |||||
| CVE-2016-10936 | 1 Wp-polls Project | 1 Wp-polls | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. | |||||
| CVE-2015-9352 | 1 Wp-polls Project | 1 Wp-polls | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The wp-polls plugin before 2.72 for WordPress has SQL injection. | |||||
| CVE-2019-15646 | 1 Rsvpmaker Project | 1 Rsvpmaker | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The rsvpmaker plugin before 6.2 for WordPress has SQL injection. | |||||
| CVE-2018-21004 | 1 Rsvpmaker Project | 1 Rsvpmaker | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. | |||||
| CVE-2019-15537 | 1 Cesnet | 1 Proxystatistics | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php. | |||||
| CVE-2015-9347 | 1 Plot | 1 Plotly | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors. | |||||
| CVE-2015-9346 | 1 Codepeople | 1 Polls Cp | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The cp-polls plugin before 1.0.5 for WordPress has XSS. | |||||
| CVE-2019-15565 | 1 Webimpacto | 1 Icommktconnector | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. | |||||
| CVE-2019-15314 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2019-08-28 | 3.5 LOW | 5.4 MEDIUM |
| tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI. | |||||
| CVE-2019-15501 | 1 Lsoft | 1 Listserv | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. | |||||
| CVE-2019-15567 | 1 Openforis | 1 Arena | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. | |||||
| CVE-2019-13274 | 2 Debian, Xymon | 2 Debian Linux, Xymon | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. | |||||
| CVE-2019-13451 | 2 Debian, Xymon | 2 Debian Linux, Xymon | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. | |||||
| CVE-2019-13452 | 2 Debian, Xymon | 2 Debian Linux, Xymon | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. | |||||
| CVE-2019-13484 | 2 Debian, Xymon | 2 Debian Linux, Xymon | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. | |||||
| CVE-2015-9345 | 1 Petersplugins | 1 Link Log | 2019-08-28 | 5.0 MEDIUM | 7.5 HIGH |
| The link-log plugin before 2.0 for WordPress has HTTP Response Splitting. | |||||
| CVE-2018-21006 | 1 Bbpress Move Topics Project | 1 Bbpress Move Topics | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
| The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | |||||
| CVE-2017-18590 | 1 Bestwebsoft | 1 Timesheet | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues. | |||||
| CVE-2018-14670 | 1 Yandex | 1 Clickhouse | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. | |||||
| CVE-2019-12791 | 1 Vestacp | 1 Control Panel | 2019-08-28 | 9.0 HIGH | 8.8 HIGH |
| A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form. | |||||
| CVE-2019-15645 | 1 Zoho | 1 Salesiq | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
| The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | |||||
| CVE-2018-21003 | 1 Themekraft | 1 Buddyforms | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | |||||
| CVE-2018-14669 | 1 Yandex | 1 Clickhouse | 2019-08-28 | 5.0 MEDIUM | 7.5 HIGH |
| ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server. | |||||
| CVE-2018-14008 | 1 Arista | 1 Eos | 2019-08-28 | 3.3 LOW | 6.5 MEDIUM |
| Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. | |||||
| CVE-2019-15644 | 1 Zoho | 1 Salesiq | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS. | |||||
| CVE-2018-20990 | 1 Tar Project | 1 Tar | 2019-08-28 | 6.4 MEDIUM | 7.5 HIGH |
| An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive. | |||||
| CVE-2019-15295 | 1 Bitdefender | 1 Antivirus 2020 | 2019-08-28 | 9.3 HIGH | 7.8 HIGH |
| An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path. | |||||
| CVE-2016-3145 | 1 Lexmark | 28 C4150, C6160, Cs720de and 25 more | 2019-08-28 | 2.1 LOW | 4.6 MEDIUM |
| Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory. | |||||
| CVE-2006-5484 | 1 Ssh | 4 Tectia Client, Tectia Connector, Tectia Manager and 1 more | 2019-08-28 | 5.0 MEDIUM | N/A |
| SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339. | |||||
| CVE-2018-21001 | 1 Bologer | 1 Anycomment | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| The anycomment plugin before 0.0.33 for WordPress has XSS. | |||||
| CVE-2019-15521 | 2 Fork-cms, Spoon-library | 2 Fork Cms, Spoon Library | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object. | |||||
| CVE-2019-15556 | 1 Social Network Project | 1 Social Network | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. | |||||
| CVE-2019-15561 | 1 Flashlingo Project | 1 Flashlingo | 2019-08-28 | 7.5 HIGH | 9.8 CRITICAL |
| FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. | |||||
| CVE-2019-15479 | 1 Status Board Project | 1 Status Board | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| Status Board 1.1.81 has reflected XSS via dashboard.ts. | |||||
| CVE-2019-15227 | 1 Getflightpath | 1 Flightpath | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions. | |||||
| CVE-2019-13176 | 1 3cx | 1 3cx | 2019-08-28 | 5.0 MEDIUM | 7.5 HIGH |
| An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS). | |||||
| CVE-2019-15062 | 1 Dolibarr | 1 Dolibarr | 2019-08-28 | 6.0 MEDIUM | 8.0 HIGH |
| An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.) | |||||
