Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15148 1 Gopro 1 Gpmf-parser 2019-08-22 4.3 MEDIUM 6.5 MEDIUM
GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c.
CVE-2019-15146 1 Gopro 1 Gpmf-parser 2019-08-22 4.3 MEDIUM 6.5 MEDIUM
GoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c.
CVE-2019-15147 1 Gopro 1 Gpmf-parser 2019-08-22 4.3 MEDIUM 6.5 MEDIUM
GoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c.
CVE-2016-10895 1 Optiontree Project 1 Optiontree 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
CVE-2017-18518 1 Bestwebsoft 1 Smtp 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
CVE-2019-1225 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-08-22 5.0 MEDIUM 7.5 HIGH
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Server Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1224.
CVE-2019-1224 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-08-22 5.0 MEDIUM 7.5 HIGH
An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Server Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1225.
CVE-2017-18568 1 Mythemeshop 1 My Wp Translate 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
CVE-2019-14682 1 Acf\ 1 Better Search Project 2019-08-22 4.3 MEDIUM 4.3 MEDIUM
The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.
CVE-2017-18517 1 Bestwebsoft 1 Pinterest 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2016-10885 1 Wp Editor Project 1 Wp Editor 2019-08-22 6.8 MEDIUM 8.8 HIGH
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
CVE-2019-3963 1 Open-emr 1 Openemr 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2015-9329 1 Soflyy 1 Wp All Import 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
CVE-2015-9331 1 Soflyy 1 Wp All Import 2019-08-22 5.0 MEDIUM 7.5 HIGH
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVE-2017-18567 1 Soflyy 1 Wp All Import 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The wp-all-import plugin before 3.4.6 for WordPress has XSS.
CVE-2019-3964 1 Open-emr 1 Openemr 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2016-10913 1 Joomunited 1 Wp Latest Posts 2019-08-22 4.3 MEDIUM 6.1 MEDIUM
The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
CVE-2015-9330 1 Soflyy 1 Wp All Import 2019-08-22 7.5 HIGH 9.8 CRITICAL
The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2015-9318 1 Getawesomesupport 1 Awesome Support 2019-08-22 5.0 MEDIUM 7.5 HIGH
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
CVE-2015-9332 1 Wordpress Uninstall Project 1 Wordpress Uninstall 2019-08-22 5.8 MEDIUM 6.5 MEDIUM
The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
CVE-2019-13578 1 Impress 1 Givewp 2019-08-22 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/payments/class-payments-query.php.
CVE-2019-14787 1 Tribulant 1 Newsletters 2019-08-22 3.5 LOW 5.4 MEDIUM
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.
CVE-2019-14788 1 Tribulant 1 Newsletter 2019-08-22 6.5 MEDIUM 8.8 HIGH
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
CVE-2019-14683 1 Codection 1 Import Users From Csv With Meta 2019-08-22 4.9 MEDIUM 5.7 MEDIUM
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
CVE-2018-18088 2 Debian, Uclouvain 2 Debian Linux, Openjpeg 2019-08-21 4.3 MEDIUM 6.5 MEDIUM
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
CVE-2017-18532 1 Bestwebsoft 1 Realty 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
CVE-2017-18533 1 Rimons Twitter Widget Project 1 Rimons Twitter Widget 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
CVE-2017-18566 1 Bestwebsoft 1 User Role 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
CVE-2015-9322 1 Erident Custom Login And Dashboard Project 1 Erident Custom Login And Dashboard 2019-08-21 6.8 MEDIUM 8.8 HIGH
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
CVE-2018-20978 1 Soflyy 1 Wp All Import 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The wp-all-import plugin before 3.4.7 for WordPress has XSS.
CVE-2019-7959 3 Adobe, Apple, Microsoft 3 Creative Cloud, Mac Os X, Windows 2019-08-21 10.0 HIGH 9.8 CRITICAL
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2019-12479 1 Twentytwenty.storage Project 1 Twentytwenty.storage 2019-08-21 6.4 MEDIUM 9.1 CRITICAL
An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize user-supplied filenames, then this issue may be exploited to read or write arbitrary files. This affects LocalStorageProvider.cs.
CVE-2016-10915 1 Supsystic 1 Popup 2019-08-21 6.8 MEDIUM 8.8 HIGH
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
CVE-2019-1010034 1 Deepsoft 1 Weblibrarian 2019-08-21 4.0 MEDIUM 6.5 MEDIUM
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.
CVE-2019-14948 1 Najeebmedia 1 Ppom For Woocommerce 2019-08-21 3.5 LOW 5.4 MEDIUM
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
CVE-2011-5328 1 User Access Manager Project 1 User Access Manager 2019-08-21 6.8 MEDIUM 8.8 HIGH
The user-access-manager plugin before 1.2 for WordPress has CSRF.
CVE-2014-10381 1 User Domain Whitelist Project 1 User Domain Whitelist 2019-08-21 6.8 MEDIUM 8.8 HIGH
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2019-14790 1 Limbcode 1 Limb-gallery 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGalleryAjax&grsAction=shortcode task parameter,
CVE-2019-14795 1 Toggle-the-title Project 1 Toggle-the-title 2019-08-21 3.5 LOW 4.8 MEDIUM
The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=update_title_options isAutoSaveValveChecked or isDisableAllPagesValveChecked parameter.
CVE-2015-9317 1 Getawesomesupport 1 Awesome Support 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
CVE-2019-14518 1 Modx 1 Evolution Cms 2019-08-21 3.5 LOW 5.4 MEDIUM
** DISPUTED ** Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel."
CVE-2015-9325 1 Bestwebsoft 1 Visitors Online 2019-08-21 7.5 HIGH 9.8 CRITICAL
The visitors-online plugin before 0.4 for WordPress has SQL injection.
CVE-2016-10904 1 Olimometer Project 1 Olimometer 2019-08-21 7.5 HIGH 9.8 CRITICAL
The olimometer plugin before 2.57 for WordPress has SQL injection.
CVE-2019-15082 1 Yofla 1 360 Product Rotation 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
CVE-2015-9326 1 Wpbusinessintelligence 1 Wp Business Intelligence 2019-08-21 7.5 HIGH 9.8 CRITICAL
The wp-business-intelligence-lite plugin before 1.6.3 for WordPress has SQL injection.
CVE-2016-10901 1 Gowebsolutions 1 Wp Customer Reviews 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
CVE-2017-18547 1 Neliosoftware 1 Nelio Ab Testing 2019-08-21 6.8 MEDIUM 8.8 HIGH
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
CVE-2015-9321 1 Wpmadeeasy 1 Shortcode Factory 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
CVE-2017-18536 1 Fullworks 1 Stop User Enumeration 2019-08-21 4.3 MEDIUM 6.1 MEDIUM
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
CVE-2019-14680 1 Mijnpress 1 Admin-renamer-extended 2019-08-21 3.5 LOW 5.7 MEDIUM
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.