Search
Total
201818 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-18491 | 1 Bestwebsoft | 1 Contact Form | 2019-08-16 | 4.3 MEDIUM | 6.1 MEDIUM |
| The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues. | |||||
| CVE-2019-14474 | 1 Eq-3 | 2 Ccu3, Ccu3 Firmware | 2019-08-16 | 5.0 MEDIUM | 7.5 HIGH |
| eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too. | |||||
| CVE-2018-1000812 | 1 Artica | 1 Integria Ims | 2019-08-16 | 4.3 MEDIUM | 8.1 HIGH |
| Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user accounts can be taken over. This attack appear to be exploitable via Network access to IntegriaIMS web interface . This vulnerability appears to have been fixed in fixed in versions released after commit f2ff0ba821644acecb893483c86a9c4d3bb75047. | |||||
| CVE-2015-9290 | 1 Freetype | 1 Freetype | 2019-08-15 | 7.5 HIGH | 9.8 CRITICAL |
| In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again. | |||||
| CVE-2019-14987 | 1 Schben | 1 Framework | 2019-08-15 | 3.5 LOW | 4.8 MEDIUM |
| Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions. | |||||
| CVE-2018-20962 | 1 Backpackforlaravel | 1 Backpack\\crud | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type. | |||||
| CVE-2019-13462 | 1 Lansweeper | 1 Lansweeper | 2019-08-15 | 6.4 MEDIUM | 9.1 CRITICAL |
| Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | |||||
| CVE-2018-20966 | 1 Booster | 1 Booster For Woocommerce | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature. | |||||
| CVE-2018-14950 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. | |||||
| CVE-2018-14951 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. | |||||
| CVE-2018-14952 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. | |||||
| CVE-2018-14953 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. | |||||
| CVE-2018-14954 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. | |||||
| CVE-2018-14955 | 1 Squirrelmail | 1 Squirrelmail | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute). | |||||
| CVE-2018-8741 | 2 Debian, Squirrelmail | 2 Debian Linux, Squirrelmail | 2019-08-15 | 6.5 MEDIUM | 8.8 HIGH |
| A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php. | |||||
| CVE-2019-14976 | 1 Icmsdev | 1 Icms | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | |||||
| CVE-2015-9305 | 1 Flippercode | 1 Google Map | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. | |||||
| CVE-2019-14950 | 1 Wp-livechat | 1 Wp Live Chat Support | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. | |||||
| CVE-2016-10879 | 1 Wp-livechat | 1 Wp Live Chat Support | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS. | |||||
| CVE-2019-14968 | 1 Txjia | 1 Imcat | 2019-08-15 | 7.5 HIGH | 9.8 CRITICAL |
| An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action. | |||||
| CVE-2018-20958 | 1 Tapplock | 2 Tapplock, Tapplock Firmware | 2019-08-15 | 3.3 LOW | 6.5 MEDIUM |
| The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device. | |||||
| CVE-2016-10877 | 1 Wp Editor Project | 1 Wp Editor | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. | |||||
| CVE-2019-14967 | 1 Frappe | 1 Frappe | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability. | |||||
| CVE-2017-18495 | 1 Mediaburst | 1 Gravity Forms | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. | |||||
| CVE-2017-14166 | 3 Canonical, Debian, Libarchive | 3 Ubuntu Linux, Debian Linux, Libarchive | 2019-08-15 | 4.3 MEDIUM | 6.5 MEDIUM |
| libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c. | |||||
| CVE-2019-11708 | 1 Mozilla | 3 Firefox, Firefox Esr, Thunderbird | 2019-08-15 | 10.0 HIGH | 10.0 CRITICAL |
| Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2. | |||||
| CVE-2019-11714 | 1 Mozilla | 1 Firefox | 2019-08-15 | 7.5 HIGH | 9.8 CRITICAL |
| Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. | |||||
| CVE-2019-11716 | 1 Mozilla | 1 Firefox | 2019-08-15 | 7.5 HIGH | 8.3 HIGH |
| Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68. | |||||
| CVE-2019-11720 | 1 Mozilla | 1 Firefox | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68. | |||||
| CVE-2019-5236 | 1 Huawei | 2 Emily-l29c, Emily-l29c Firmware | 2019-08-15 | 6.8 MEDIUM | 6.3 MEDIUM |
| Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal. | |||||
| CVE-2017-18497 | 1 W3eden | 1 Live Forms | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The liveforms plugin before 3.4.0 for WordPress has XSS. | |||||
| CVE-2017-18496 | 1 Bestwebsoft | 1 Htaccess | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues. | |||||
| CVE-2017-18494 | 1 Bestwebsoft | 1 Custom Search | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues. | |||||
| CVE-2017-18487 | 1 Google Adsense Project | 1 Google Adsense | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The adsense-plugin (aka Google AdSense) plugin before 1.44 for WordPress has multiple XSS issues. | |||||
| CVE-2016-10866 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues. | |||||
| CVE-2017-18507 | 1 Wp-livechat | 1 Wp Live Chat Support | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS. | |||||
| CVE-2018-20858 | 1 Edx | 1 Recommender | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| Recommender before 2018-07-18 allows XSS. | |||||
| CVE-2018-20964 | 1 Codepeople | 1 Contact Form Email | 2019-08-15 | 6.8 MEDIUM | 8.8 HIGH |
| The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | |||||
| CVE-2018-20963 | 1 Codepeople | 1 Contact Form Email | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The contact-form-to-email plugin before 1.2.66 for WordPress has XSS. | |||||
| CVE-2017-18498 | 1 Presstigers | 1 Simple Job Board | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The simple-job-board plugin before 2.4.4 for WordPress has reflected XSS via keyword search. | |||||
| CVE-2017-18488 | 1 Backup-guard | 1 Backup Guard | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Backup Guard plugin before 1.1.47 for WordPress has multiple XSS issues. | |||||
| CVE-2019-10352 | 1 Jenkins | 1 Jenkins | 2019-08-15 | 4.0 MEDIUM | 6.5 MEDIUM |
| A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build. | |||||
| CVE-2017-18485 | 1 Elementalpath | 2 Cognitoys Dino, Cognitoys Dino Firmware | 2019-08-15 | 5.8 MEDIUM | 5.4 MEDIUM |
| Cognitoys Dino devices allow profiles_add.html CSRF. | |||||
| CVE-2019-10182 | 2 Icedtea-web Project, Redhat | 6 Icedtea-web, Enterprise Linux Desktop, Enterprise Linux Server and 3 more | 2019-08-15 | 5.8 MEDIUM | 6.5 MEDIUM |
| It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user. | |||||
| CVE-2017-18484 | 1 Elementalpath | 2 Cognitoys Dino, Cognitoys Dino Firmware | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cognitoys Dino devices allow XSS via the SSID. | |||||
| CVE-2016-10862 | 1 Neetcables | 2 Airstream Nas, Airstream Nas Firmware | 2019-08-15 | 6.8 MEDIUM | 8.8 HIGH |
| Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page. | |||||
| CVE-2015-9292 | 1 6kbbs | 1 6kbbs | 2019-08-15 | 6.8 MEDIUM | 8.8 HIGH |
| 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). | |||||
| CVE-2019-14769 | 1 Backdropcms | 1 Backdrop | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typically an administrative permission.) | |||||
| CVE-2019-14731 | 1 Cnezsoft | 1 Zentao | 2019-08-15 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box. | |||||
| CVE-2016-10865 | 1 23systems | 1 Lightbox Plus Colorbox | 2019-08-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS. | |||||
