Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18550 1 Linux 1 Linux Kernel 2019-08-23 2.1 LOW 5.5 MEDIUM
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo structure.
CVE-2017-18549 1 Linux 1 Linux Kernel 2019-08-23 2.1 LOW 5.5 MEDIUM
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure.
CVE-2018-13137 1 Wp-events-plugin 1 Events Manager 2019-08-23 3.5 LOW 4.8 MEDIUM
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
CVE-2019-12240 1 Virim Project 1 Virim 2019-08-23 7.5 HIGH 9.8 CRITICAL
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.
CVE-2019-14799 1 Foliovision 1 Fv Flowplayer Video Player 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
CVE-2019-15112 1 Wp-slimstat 1 Slimstat Analytics 2019-08-23 4.3 MEDIUM 6.1 MEDIUM
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
CVE-2019-5924 1 Rednao 1 Smart Forms 2019-08-23 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
CVE-2019-0334 1 Sap 1 Businessobjects Business Intelligence 2019-08-22 4.9 MEDIUM 5.4 MEDIUM
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malicious script which when executed later could potentially allow a user to escalate privileges via session hijacking. The attacker could also access other sensitive information, leading to Stored Cross Site Scripting.
CVE-2019-2121 1 Google 1 Android 2019-08-22 6.9 MEDIUM 7.0 HIGH
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-131105245.
CVE-2019-2129 1 Google 1 Android 2019-08-22 4.3 MEDIUM 6.5 MEDIUM
In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-124781927.
CVE-2019-12797 1 Elmelectronics 2 Elm27, Elm27 Firmware 2019-08-22 7.5 HIGH 9.8 CRITICAL
A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.
CVE-2019-13588 1 Wikindx Project 1 Wikindx 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via the PagingStart parameter.
CVE-2019-15231 2019-08-22 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of CVE-2019-15107. Notes: All CVE users should reference CVE-2019-15107 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2019-2122 1 Google 1 Android 2019-08-22 6.9 MEDIUM 7.3 HIGH
In LockTaskController.lockKeyguardIfNeeded of the LockTaskController.java, there was a difference in the handling of the default case between the WindowManager and the Settings. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127605586.
CVE-2012-6714 1 Count Per Day Project 1 Count Per Day 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The count-per-day plugin before 3.2.3 for WordPress has XSS via search words.
CVE-2012-6715 1 Formbuilder Project 1 Formbuilder 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The formbuilder plugin before 0.9.1 for WordPress has XSS via a Referer header.
CVE-2014-10380 1 Cozmoslabs 1 Profile Builder 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The profile-builder plugin before 1.1.66 for WordPress has multiple XSS issues in forms.
CVE-2015-9328 1 Cozmoslabs 1 Profile Builder 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The profile-builder plugin before 2.2.5 for WordPress has XSS.
CVE-2016-10898 1 Fabrix 1 Total Security 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The total-security plugin before 3.4.1 for WordPress has XSS.
CVE-2016-10899 1 Fabrix 1 Total Security 2019-08-22 5.0 MEDIUM 5.3 MEDIUM
The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
CVE-2016-10910 1 Formbuilder Project 1 Formbuilder 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
CVE-2016-10911 1 Cozmoslabs 1 Profile Builder 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
CVE-2016-10902 1 Gowebsolutions 1 Wp Customer Reviews 2019-08-22 6.8 MEDIUM 8.8 HIGH
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10912 1 Matchboxdesigngroup 1 Universal Analytics 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The universal-analytics plugin before 1.3.1 for WordPress has XSS.
CVE-2017-18516 1 Bestwebsoft 1 Linkedin 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2017-18522 1 Eelv Newsletter Project 1 Eelv Newsletter 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
CVE-2017-18524 1 Football Pool Project 1 Football Pool 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
CVE-2017-18529 1 Bestwebsoft 1 Promobar 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
CVE-2019-3965 1 Open-emr 1 Openemr 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2017-18519 1 Marvinlabs 1 Wp Customer Area 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
CVE-2014-10379 1 Duplicate Post Project 1 Duplicate Post 2019-08-22 7.5 HIGH 9.8 CRITICAL
The duplicate-post plugin before 2.6 for WordPress has SQL injection.
CVE-2017-18561 1 Embed Images In Comments Project 1 Embed Images In Comments 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The embed-comment-images plugin before 0.6 for WordPress has XSS.
CVE-2017-18562 1 Bestwebsoft 1 Error Log Viewer 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
CVE-2018-20970 1 Bestwebsoft 1 Pdf \& Print 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The pdf-print plugin before 2.0.3 for WordPress has multiple XSS issues.
CVE-2014-10378 1 Duplicate Post Project 1 Duplicate Post 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The duplicate-post plugin before 2.6 for WordPress has XSS.
CVE-2016-10897 1 Sermon Browser Project 1 Sermon Browser 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
CVE-2017-18525 1 Megamenu 1 Max Mega Menu 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The megamenu plugin before 2.4 for WordPress has XSS.
CVE-2017-18535 1 Smokesignal Project 1 Smokesignal 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The smokesignal plugin before 1.2.7 for WordPress has XSS.
CVE-2016-10896 1 Clogica 1 Seo Redirection 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The seo-redirection plugin before 4.3 for WordPress has stored XSS.
CVE-2017-18531 1 Raygun 1 Raygun4wp 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.
CVE-2017-18530 1 Bestwebsoft 1 Rating 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
CVE-2017-18528 1 Bestwebsoft 1 Pdf \& Print 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
CVE-2017-18527 1 Bestwebsoft 1 Pagination 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
CVE-2017-18526 1 Lamp-solutions 1 Moreads Se 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The moreads-se plugin before 1.4.7 for WordPress has XSS.
CVE-2017-18569 1 Mythemeshop 1 My Wp Translate 2019-08-22 6.8 MEDIUM 8.8 HIGH
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
CVE-2016-10914 1 Add From Server Project 1 Add From Server 2019-08-22 6.8 MEDIUM 8.8 HIGH
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
CVE-2017-18523 1 Eelv Newsletter Project 1 Eelv Newsletter 2019-08-22 6.8 MEDIUM 8.8 HIGH
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
CVE-2017-18520 1 Wp-kama 1 Democracy Poll 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
CVE-2015-9319 1 Greg\'s High Performance Seo Project 1 Greg\'s High Performance Seo 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
CVE-2019-15238 1 Cformsii Project 1 Cformsii 2019-08-22 6.8 MEDIUM 8.8 HIGH
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.