Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-21002 1 Joomsky 1 Js Help Desk 2019-08-28 6.8 MEDIUM 8.8 HIGH
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2012-6718 1 Sharebar Project 1 Sharebar 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
CVE-2012-6719 1 Sharebar Project 1 Sharebar 2019-08-28 7.5 HIGH 9.8 CRITICAL
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
CVE-2018-14062 1 Cospas-sarsat 1 Cospas-sarsat System 2019-08-28 9.4 HIGH 9.1 CRITICAL
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.
CVE-2019-15568 1 Idseq 1 Idseq-web 2019-08-28 7.5 HIGH 9.8 CRITICAL
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2018-18573 1 Oscommerce 1 Oscommerce 2019-08-28 6.5 MEDIUM 7.2 HIGH
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
CVE-2014-10395 1 Codepeople 1 Polls Cp 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2015-9342 1 Impress 1 Wp Rollback 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
CVE-2019-15659 1 Genetechsolutions 1 Pie Register 2019-08-28 7.5 HIGH 9.8 CRITICAL
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2015-9349 1 Cksource 1 Ckeditor 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
CVE-2019-15660 1 Wp-members Project 1 Wp-members 2019-08-28 6.8 MEDIUM 8.8 HIGH
The wp-members plugin before 3.2.8 for WordPress has CSRF.
CVE-2015-9351 1 Slickremix 1 Feed Them Social 2019-08-28 7.5 HIGH 9.8 CRITICAL
The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
CVE-2015-9350 1 Slickremix 1 Feed Them Social 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
CVE-2016-10936 1 Wp-polls Project 1 Wp-polls 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
CVE-2015-9352 1 Wp-polls Project 1 Wp-polls 2019-08-28 7.5 HIGH 9.8 CRITICAL
The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2019-15646 1 Rsvpmaker Project 1 Rsvpmaker 2019-08-28 7.5 HIGH 9.8 CRITICAL
The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
CVE-2018-21004 1 Rsvpmaker Project 1 Rsvpmaker 2019-08-28 7.5 HIGH 9.8 CRITICAL
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
CVE-2019-15537 1 Cesnet 1 Proxystatistics 2019-08-28 7.5 HIGH 9.8 CRITICAL
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2015-9347 1 Plot 1 Plotly 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
CVE-2015-9346 1 Codepeople 1 Polls Cp 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The cp-polls plugin before 1.0.5 for WordPress has XSS.
CVE-2019-15565 1 Webimpacto 1 Icommktconnector 2019-08-28 7.5 HIGH 9.8 CRITICAL
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
CVE-2019-15314 1 Tiki 1 Tikiwiki Cms\/groupware 2019-08-28 3.5 LOW 5.4 MEDIUM
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
CVE-2019-15501 1 Lsoft 1 Listserv 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CVE-2019-15567 1 Openforis 1 Arena 2019-08-28 7.5 HIGH 9.8 CRITICAL
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2019-13274 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
CVE-2019-13451 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CVE-2019-13452 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CVE-2019-13484 2 Debian, Xymon 2 Debian Linux, Xymon 2019-08-28 7.5 HIGH 9.8 CRITICAL
In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.
CVE-2015-9345 1 Petersplugins 1 Link Log 2019-08-28 5.0 MEDIUM 7.5 HIGH
The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
CVE-2018-21006 1 Bbpress Move Topics Project 1 Bbpress Move Topics 2019-08-28 6.8 MEDIUM 8.8 HIGH
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
CVE-2017-18590 1 Bestwebsoft 1 Timesheet 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
CVE-2018-14670 1 Yandex 1 Clickhouse 2019-08-28 7.5 HIGH 9.8 CRITICAL
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
CVE-2019-12791 1 Vestacp 1 Control Panel 2019-08-28 9.0 HIGH 8.8 HIGH
A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root via the password reset form.
CVE-2019-15645 1 Zoho 1 Salesiq 2019-08-28 6.8 MEDIUM 8.8 HIGH
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
CVE-2018-21003 1 Themekraft 1 Buddyforms 2019-08-28 7.5 HIGH 9.8 CRITICAL
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2018-14669 1 Yandex 1 Clickhouse 2019-08-28 5.0 MEDIUM 7.5 HIGH
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
CVE-2018-14008 1 Arista 1 Eos 2019-08-28 3.3 LOW 6.5 MEDIUM
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
CVE-2019-15644 1 Zoho 1 Salesiq 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
CVE-2018-20990 1 Tar Project 1 Tar 2019-08-28 6.4 MEDIUM 7.5 HIGH
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
CVE-2019-15295 1 Bitdefender 1 Antivirus 2020 2019-08-28 9.3 HIGH 7.8 HIGH
An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path.
CVE-2016-3145 1 Lexmark 28 C4150, C6160, Cs720de and 25 more 2019-08-28 2.1 LOW 4.6 MEDIUM
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.
CVE-2006-5484 1 Ssh 4 Tectia Client, Tectia Connector, Tectia Manager and 1 more 2019-08-28 5.0 MEDIUM N/A
SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.
CVE-2018-21001 1 Bologer 1 Anycomment 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2019-15521 2 Fork-cms, Spoon-library 2 Fork Cms, Spoon Library 2019-08-28 7.5 HIGH 9.8 CRITICAL
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing an object.
CVE-2019-15556 1 Social Network Project 1 Social Network 2019-08-28 7.5 HIGH 9.8 CRITICAL
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
CVE-2019-15561 1 Flashlingo Project 1 Flashlingo 2019-08-28 7.5 HIGH 9.8 CRITICAL
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
CVE-2019-15479 1 Status Board Project 1 Status Board 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-15227 1 Getflightpath 1 Flightpath 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-13176 1 3cx 1 3cx 2019-08-28 5.0 MEDIUM 7.5 HIGH
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).
CVE-2019-15062 1 Dolibarr 1 Dolibarr 2019-08-28 6.0 MEDIUM 8.0 HIGH
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)