Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18491 1 Bestwebsoft 1 Contact Form 2019-08-16 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
CVE-2019-14474 1 Eq-3 2 Ccu3, Ccu3 Firmware 2019-08-16 5.0 MEDIUM 7.5 HIGH
eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too.
CVE-2018-1000812 1 Artica 1 Integria Ims 2019-08-16 4.3 MEDIUM 8.1 HIGH
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user accounts can be taken over. This attack appear to be exploitable via Network access to IntegriaIMS web interface . This vulnerability appears to have been fixed in fixed in versions released after commit f2ff0ba821644acecb893483c86a9c4d3bb75047.
CVE-2015-9290 1 Freetype 1 Freetype 2019-08-15 7.5 HIGH 9.8 CRITICAL
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
CVE-2019-14987 1 Schben 1 Framework 2019-08-15 3.5 LOW 4.8 MEDIUM
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
CVE-2018-20962 1 Backpackforlaravel 1 Backpack\\crud 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
CVE-2019-13462 1 Lansweeper 1 Lansweeper 2019-08-15 6.4 MEDIUM 9.1 CRITICAL
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
CVE-2018-20966 1 Booster 1 Booster For Woocommerce 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-14950 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
CVE-2018-14951 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
CVE-2018-14952 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
CVE-2018-14953 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
CVE-2018-14954 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
CVE-2018-14955 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
CVE-2018-8741 2 Debian, Squirrelmail 2 Debian Linux, Squirrelmail 2019-08-15 6.5 MEDIUM 8.8 HIGH
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
CVE-2019-14976 1 Icmsdev 1 Icms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
CVE-2015-9305 1 Flippercode 1 Google Map 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
CVE-2019-14950 1 Wp-livechat 1 Wp Live Chat Support 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
CVE-2016-10879 1 Wp-livechat 1 Wp Live Chat Support 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
CVE-2019-14968 1 Txjia 1 Imcat 2019-08-15 7.5 HIGH 9.8 CRITICAL
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
CVE-2018-20958 1 Tapplock 2 Tapplock, Tapplock Firmware 2019-08-15 3.3 LOW 6.5 MEDIUM
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
CVE-2016-10877 1 Wp Editor Project 1 Wp Editor 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
CVE-2019-14967 1 Frappe 1 Frappe 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
CVE-2017-18495 1 Mediaburst 1 Gravity Forms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
CVE-2017-14166 3 Canonical, Debian, Libarchive 3 Ubuntu Linux, Debian Linux, Libarchive 2019-08-15 4.3 MEDIUM 6.5 MEDIUM
libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
CVE-2019-11708 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2019-08-15 10.0 HIGH 10.0 CRITICAL
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
CVE-2019-11714 1 Mozilla 1 Firefox 2019-08-15 7.5 HIGH 9.8 CRITICAL
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.
CVE-2019-11716 1 Mozilla 1 Firefox 2019-08-15 7.5 HIGH 8.3 HIGH
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
CVE-2019-11720 1 Mozilla 1 Firefox 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.
CVE-2019-5236 1 Huawei 2 Emily-l29c, Emily-l29c Firmware 2019-08-15 6.8 MEDIUM 6.3 MEDIUM
Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.
CVE-2017-18497 1 W3eden 1 Live Forms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The liveforms plugin before 3.4.0 for WordPress has XSS.
CVE-2017-18496 1 Bestwebsoft 1 Htaccess 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
CVE-2017-18494 1 Bestwebsoft 1 Custom Search 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.
CVE-2017-18487 1 Google Adsense Project 1 Google Adsense 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues.
CVE-2016-10866 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
CVE-2017-18507 1 Wp-livechat 1 Wp Live Chat Support 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.
CVE-2018-20858 1 Edx 1 Recommender 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
Recommender before 2018-07-18 allows XSS.
CVE-2018-20964 1 Codepeople 1 Contact Form Email 2019-08-15 6.8 MEDIUM 8.8 HIGH
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
CVE-2018-20963 1 Codepeople 1 Contact Form Email 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
CVE-2017-18498 1 Presstigers 1 Simple Job Board 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search.
CVE-2017-18488 1 Backup-guard 1 Backup Guard 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues.
CVE-2019-10352 1 Jenkins 1 Jenkins 2019-08-15 4.0 MEDIUM 6.5 MEDIUM
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
CVE-2017-18485 1 Elementalpath 2 Cognitoys Dino, Cognitoys Dino Firmware 2019-08-15 5.8 MEDIUM 5.4 MEDIUM
Cognitoys Dino devices allow profiles_add.html CSRF.
CVE-2019-10182 2 Icedtea-web Project, Redhat 6 Icedtea-web, Enterprise Linux Desktop, Enterprise Linux Server and 3 more 2019-08-15 5.8 MEDIUM 6.5 MEDIUM
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
CVE-2017-18484 1 Elementalpath 2 Cognitoys Dino, Cognitoys Dino Firmware 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
Cognitoys Dino devices allow XSS via the SSID.
CVE-2016-10862 1 Neetcables 2 Airstream Nas, Airstream Nas Firmware 2019-08-15 6.8 MEDIUM 8.8 HIGH
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
CVE-2015-9292 1 6kbbs 1 6kbbs 2019-08-15 6.8 MEDIUM 8.8 HIGH
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
CVE-2019-14769 1 Backdropcms 1 Backdrop 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typically an administrative permission.)
CVE-2019-14731 1 Cnezsoft 1 Zentao 2019-08-15 3.5 LOW 5.4 MEDIUM
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
CVE-2016-10865 1 23systems 1 Lightbox Plus Colorbox 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.