CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2014-4519

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the 'page' parameter.

    Published: 27 Dec 2019
    5.3
    Medium

    CVE-2013-4868

    Last Modified: 21 Nov 2024

    Karotz API 12.07.19.00: Session Token Information Disclosure

    Published: 27 Dec 2019
    6.3
    Medium

    CVE-2013-4867

    Last Modified: 21 Nov 2024

    Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

    Published: 27 Dec 2019
    8.1
    High

    CVE-2013-4859

    Last Modified: 21 Nov 2024

    INSTEON Hub 2242-222 lacks Web and API authentication

    Published: 27 Dec 2019
    8.8
    High

    CVE-2013-4796

    Last Modified: 21 Nov 2024

    ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request

    Published: 27 Dec 2019
    9.8
    Critical

    CVE-2013-4621

    Last Modified: 21 Nov 2024

    Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities

    Published: 27 Dec 2019
    9.8
    Critical

    CVE-2013-4743

    Last Modified: 21 Nov 2024

    Static HTTP Server 1.0 has a Local Overflow

    Published: 27 Dec 2019
    4.3
    Medium

    CVE-2013-4764

    Last Modified: 21 Nov 2024

    Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.

    Published: 27 Dec 2019
    4.6
    Medium

    CVE-2013-4763

    Last Modified: 21 Nov 2024

    Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2013-4692

    Last Modified: 21 Nov 2024

    Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS

    Published: 27 Dec 2019
    7.8
    High

    CVE-2013-4695

    Last Modified: 21 Nov 2024

    Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2013-4693

    Last Modified: 21 Nov 2024

    WordPress Xorbin Digital Flash Clock 1.0 has XSS

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2013-4665

    Last Modified: 21 Nov 2024

    SPBAS Business Automation Software 2012 has CSRF.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2013-4664

    Last Modified: 21 Nov 2024

    SPBAS Business Automation Software 2012 has XSS.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2013-4691

    Last Modified: 21 Nov 2024

    Sencha Labs Connect has XSS with connect.methodOverride()

    Published: 27 Dec 2019
    7.8
    High

    CVE-2019-16896

    Last Modified: 21 Nov 2024

    In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.

    Published: 27 Dec 2019
    4.8
    Medium

    CVE-2016-1000029

    Last Modified: 21 Nov 2024

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).

    Published: 27 Dec 2019
    4.8
    Medium

    CVE-2016-1000028

    Last Modified: 21 Nov 2024

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2014-4559

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2014-4525

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2014-4523

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 27 Dec 2019
    9.8
    Critical

    CVE-2019-19781

    Last Modified: 7 Nov 2025

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

    Published: 27 Dec 2019
    9.8
    Critical

    CVE-2019-20041

    Last Modified: 21 Nov 2024

    wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2019-20042

    Last Modified: 21 Nov 2024

    In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

    Published: 27 Dec 2019
    4.3
    Medium

    CVE-2019-20043

    Last Modified: 21 Nov 2024

    In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20016

    Last Modified: 21 Nov 2024

    libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20017

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20018

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20019

    Last Modified: 21 Nov 2024

    An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20020

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.

    Published: 27 Dec 2019
    5.5
    Medium

    CVE-2019-20021

    Last Modified: 11 Apr 2025

    A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20022

    Last Modified: 24 Apr 2026

    An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20024

    Last Modified: 24 Apr 2026

    A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20023

    Last Modified: 24 Apr 2026

    A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20009

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.

    Published: 27 Dec 2019
    8.8
    High

    CVE-2019-20011

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20012

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20013

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.

    Published: 27 Dec 2019
    8.8
    High

    CVE-2019-20014

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.

    Published: 27 Dec 2019
    6.5
    Medium

    CVE-2019-20015

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.

    Published: 27 Dec 2019
    8.8
    High

    CVE-2019-20010

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.

    Published: 27 Dec 2019
    7.5
    High

    CVE-2020-35342

    Last Modified: 21 Nov 2024

    GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

    Published: 27 Dec 2019
    6.1
    Medium

    CVE-2020-35494

    Last Modified: 21 Nov 2024

    There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.

    Published: 27 Dec 2019
    9.8
    Critical

    CVE-2013-3088

    Last Modified: 21 Nov 2024

    Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

    Published: 26 Dec 2019
    5.4
    Medium

    CVE-2019-20008

    Last Modified: 21 Nov 2024

    In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.

    Published: 26 Dec 2019
    9.8
    Critical

    CVE-2013-3085

    Last Modified: 21 Nov 2024

    An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

    Published: 26 Dec 2019
    6.5
    Medium

    CVE-2019-20005

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\0' character (where the processing of a string was finished).

    Published: 26 Dec 2019
    7.5
    High

    CVE-2019-20006

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.

    Published: 26 Dec 2019
    6.5
    Medium

    CVE-2019-20007

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).

    Published: 26 Dec 2019
    8.8
    High

    CVE-2013-2011

    Last Modified: 21 Nov 2024

    WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.

    Published: 26 Dec 2019