Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15487 1 Schoolexperience 1 Department For Education School Experience 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15492 1 It-novum 1 Openitcockpit 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15535 1 Hostosm 1 Tasking Manager 2019-08-26 7.5 HIGH 9.8 CRITICAL
Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.
CVE-2019-15489 1 Laracom 1 Laracom 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CVE-2019-15481 1 Kimai 1 Kimai 2 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Kimai v2 before 1.1 has XSS via a timesheet description.
CVE-2019-15477 1 Jooby 1 Jooby 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-2135 1 Google 1 Android 2019-08-26 7.1 HIGH 5.5 MEDIUM
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-125900276.
CVE-2019-15105 1 Zohocorp 1 Manageengine Applications Manager 2019-08-26 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
CVE-2019-2133 1 Google 1 Android 2019-08-26 9.3 HIGH 7.8 HIGH
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-132082342.
CVE-2016-10922 1 Visser 1 Store Toolkit For Woocommerce 2019-08-26 7.5 HIGH 9.8 CRITICAL
The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2015-9337 1 Cozmoslabs 1 Profile Builder 2019-08-26 5.0 MEDIUM 7.5 HIGH
The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
CVE-2019-15486 1 Django Js Reverse Project 1 Django Js Reserve 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
CVE-2019-15480 1 Domoticz 1 Domoticz 2019-08-26 3.5 LOW 5.4 MEDIUM
Domoticz 4.10717 has XSS via item.Name.
CVE-2014-10384 1 Memphis Documents Library Project 1 Memphis Documents Library 2019-08-26 7.5 HIGH 9.8 CRITICAL
The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
CVE-2014-10383 1 Memphis Documents Library Project 1 Memphis Documents Library 2019-08-26 7.5 HIGH 9.8 CRITICAL
The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
CVE-2014-10385 1 Memphis Documents Library Project 1 Memphis Documents Library 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2013-7482 1 Reflex Gallery Project 1 Reflex Gallery 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
CVE-2019-15317 1 Impress 1 Givewp 2019-08-26 3.5 LOW 5.4 MEDIUM
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
CVE-2014-10387 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-26 7.5 HIGH 9.8 CRITICAL
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
CVE-2019-15324 1 Ad Inserter Project 1 Ad Inserter 2019-08-26 6.5 MEDIUM 8.8 HIGH
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
CVE-2019-15095 1 Diaowen 1 Dwsurvey 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
CVE-2019-15534 1 Raml-module-builder Project 1 Raml-module-builder 2019-08-26 7.5 HIGH 9.8 CRITICAL
Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2016-6154 2 Microsoft, Watchguard 2 Windows, Fireware 2019-08-26 5.8 MEDIUM 6.1 MEDIUM
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2018-20981 1 Ninjaforms 1 Ninja Forms 2019-08-26 6.4 MEDIUM 9.1 CRITICAL
The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
CVE-2019-15532 1 Gchq 1 Cyberchef 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
CVE-2018-20980 1 Ninjaforms 1 Ninja Forms 2019-08-26 5.0 MEDIUM 7.5 HIGH
The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
CVE-2017-18575 1 Newstatpress Project 1 Newstatpress 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
CVE-2017-18574 1 Ninjaforms 1 Ninja Forms 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
CVE-2017-18573 1 Simplerealtytheme 1 Simple Login Log 2019-08-26 7.5 HIGH 9.8 CRITICAL
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
CVE-2017-18572 1 Sir 1 Gnucommerce 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The gnucommerce plugin before 1.4.2 for WordPress has XSS.
CVE-2017-18571 1 Search Everything Project 1 Search Everything 2019-08-26 7.5 HIGH 9.8 CRITICAL
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
CVE-2019-15478 1 Status Board Project 1 Status Board 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Status Board 1.1.81 has reflected XSS via logic.ts.
CVE-2016-10921 1 Ays-pro 1 Photo Gallery 2019-08-26 7.5 HIGH 9.8 CRITICAL
The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10920 1 Sir 1 Gnucommerce 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
CVE-2018-20985 1 Payeezy 1 Wp Payeezy Pay 2019-08-26 7.5 HIGH 9.8 CRITICAL
The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
CVE-2016-10919 1 Wassup Real Time Analytics Project 1 Wassup Real Time Analytics 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.
CVE-2017-18584 1 Post Pay Counter Project 1 Post Pay Counter 2019-08-26 5.0 MEDIUM 7.5 HIGH
The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.
CVE-2018-20983 1 Meowapps 1 Wp Retina 2x 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
CVE-2017-18583 1 Post Pay Counter Project 1 Post Pay Counter 2019-08-26 7.5 HIGH 9.8 CRITICAL
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
CVE-2017-18582 1 Time Sheets Project 1 Time Sheets 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
CVE-2016-10926 1 Neliosoftware 1 Nelio Ab Testing 2019-08-26 6.4 MEDIUM 10.0 CRITICAL
The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10927 1 Neliosoftware 1 Nelio Ab Testing 2019-08-26 6.4 MEDIUM 10.0 CRITICAL
The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
CVE-2019-13031 2 Debian, Lemonldap-ng 2 Debian Linux, Lemonldap\ 2019-08-26 6.8 MEDIUM 8.1 HIGH
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
CVE-2016-10918 1 Supsystic 1 Photo Gallery 2019-08-26 6.8 MEDIUM 8.8 HIGH
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2016-10916 1 Codepeople 1 Appointment Booking Calendar 2019-08-26 7.5 HIGH 9.8 CRITICAL
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
CVE-2019-5594 1 Fortinet 1 Fortinac 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-0338 1 Sap 1 Gateway 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
CVE-2019-0337 1 Sap 1 Netweaver Process Integration 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs and allows an attacker to execute malicious scripts in the url thereby resulting in Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2019-0335 1 Sap 1 Businessobjects Business Intelligence 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker to store a malicious payload within the description field of a user account. The payload is triggered when the mouse cursor is moved over the description field in the list, when generating the little yellow informational pop up box, resulting in Stored Cross Site Scripting Attack.
CVE-2018-20975 1 Fatfreecrm 1 Fat Free Crm 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Fat Free CRM before 0.18.1 has XSS in the tags_helper in app/helpers/tags_helper.rb.