CVE-2014-4519
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in the Conversador plugin 2.61 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the 'page' parameter.
CVE-2013-4868
Last Modified: 21 Nov 2024Karotz API 12.07.19.00: Session Token Information Disclosure
CVE-2013-4867
Last Modified: 21 Nov 2024Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
CVE-2013-4859
Last Modified: 21 Nov 2024INSTEON Hub 2242-222 lacks Web and API authentication
CVE-2013-4796
Last Modified: 21 Nov 2024ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
CVE-2013-4621
Last Modified: 21 Nov 2024Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
CVE-2013-4743
Last Modified: 21 Nov 2024Static HTTP Server 1.0 has a Local Overflow
CVE-2013-4764
Last Modified: 21 Nov 2024Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
CVE-2013-4763
Last Modified: 21 Nov 2024Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
CVE-2013-4692
Last Modified: 21 Nov 2024Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
CVE-2013-4695
Last Modified: 21 Nov 2024Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
CVE-2013-4693
Last Modified: 21 Nov 2024WordPress Xorbin Digital Flash Clock 1.0 has XSS
CVE-2013-4665
Last Modified: 21 Nov 2024SPBAS Business Automation Software 2012 has CSRF.
CVE-2013-4664
Last Modified: 21 Nov 2024SPBAS Business Automation Software 2012 has XSS.
CVE-2013-4691
Last Modified: 21 Nov 2024Sencha Labs Connect has XSS with connect.methodOverride()
CVE-2019-16896
Last Modified: 21 Nov 2024In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
CVE-2016-1000029
Last Modified: 21 Nov 2024Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).
CVE-2016-1000028
Last Modified: 21 Nov 2024Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
CVE-2014-4559
Last Modified: 21 Nov 2024Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter.
CVE-2014-4525
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.
CVE-2014-4523
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVE-2019-19781
Last Modified: 7 Nov 2025An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
CVE-2019-20041
Last Modified: 21 Nov 2024wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
CVE-2019-20042
Last Modified: 21 Nov 2024In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
CVE-2019-20043
Last Modified: 21 Nov 2024In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
CVE-2019-20016
Last Modified: 21 Nov 2024libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue.
CVE-2019-20017
Last Modified: 21 Nov 2024A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.
CVE-2019-20018
Last Modified: 21 Nov 2024A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.
CVE-2019-20019
Last Modified: 21 Nov 2024An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
CVE-2019-20020
Last Modified: 21 Nov 2024A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.
CVE-2019-20021
Last Modified: 11 Apr 2025A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
CVE-2019-20022
Last Modified: 24 Apr 2026An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
CVE-2019-20024
Last Modified: 24 Apr 2026A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
CVE-2019-20023
Last Modified: 24 Apr 2026A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
CVE-2019-20009
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
CVE-2019-20011
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
CVE-2019-20012
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
CVE-2019-20013
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
CVE-2019-20014
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
CVE-2019-20015
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
CVE-2019-20010
Last Modified: 21 Nov 2024An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
CVE-2020-35342
Last Modified: 21 Nov 2024GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
CVE-2020-35494
Last Modified: 21 Nov 2024There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.
CVE-2013-3088
Last Modified: 21 Nov 2024Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
CVE-2019-20008
Last Modified: 21 Nov 2024In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
CVE-2013-3085
Last Modified: 21 Nov 2024An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
CVE-2019-20005
Last Modified: 21 Nov 2024An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\0' character (where the processing of a string was finished).
CVE-2019-20006
Last Modified: 21 Nov 2024An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.
CVE-2019-20007
Last Modified: 21 Nov 2024An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).
CVE-2013-2011
Last Modified: 21 Nov 2024WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
