CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-9521

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9522

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9523

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9524

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9525

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9526

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9527

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9528

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9529

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9530

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9531

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9532

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9533

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9534

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9535

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2019-16975

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2015-9536

    Last Modified: 7 Feb 2025

    The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

    Published: 23 Oct 2019
    9.8
    Critical

    CVE-2019-11933

    Last Modified: 21 Nov 2024

    A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-11283

    Last Modified: 21 Nov 2024

    Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.

    Published: 23 Oct 2019
    4.3
    Medium

    CVE-2019-11282

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.

    Published: 23 Oct 2019
    9.8
    Critical

    CVE-2019-18344

    Last Modified: 21 Nov 2024

    Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2019-16976

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-18280

    Last Modified: 21 Nov 2024

    Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User action at the admin/modules/user/controller.php?action=add URI.

    Published: 23 Oct 2019
    7.8
    High

    CVE-2019-18278

    Last Modified: 21 Nov 2024

    When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-18220

    Last Modified: 21 Nov 2024

    Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2019-18219

    Last Modified: 21 Nov 2024

    Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.

    Published: 23 Oct 2019
    7.8
    High

    CVE-2019-10476

    Last Modified: 21 Nov 2024

    Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 23 Oct 2019
    6.1
    Medium

    CVE-2019-10475

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

    Published: 23 Oct 2019
    4.3
    Medium

    CVE-2019-10474

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10472

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 23 Oct 2019
    4.3
    Medium

    CVE-2019-10473

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10470

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-10471

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10469

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-10468

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 23 Oct 2019
    8.1
    High

    CVE-2019-10466

    Last Modified: 21 Nov 2024

    An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins agent, server-side request forgery, or denial-of-service attacks.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10467

    Last Modified: 21 Nov 2024

    Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 23 Oct 2019
    8.8
    High

    CVE-2019-10464

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.

    Published: 23 Oct 2019
    4.3
    Medium

    CVE-2019-10465

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.

    Published: 23 Oct 2019
    8.1
    High

    CVE-2019-10462

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10463

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

    Published: 23 Oct 2019
    7.8
    High

    CVE-2019-10461

    Last Modified: 21 Nov 2024

    Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 23 Oct 2019
    7.8
    High

    CVE-2019-10460

    Last Modified: 21 Nov 2024

    Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-10459

    Last Modified: 21 Nov 2024

    Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

    Published: 23 Oct 2019
    6.5
    Medium

    CVE-2019-14276

    Last Modified: 21 Nov 2024

    WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.

    Published: 23 Oct 2019
    3.7
    Low

    CVE-2019-14834

    Last Modified: 21 Nov 2024

    A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.

    Published: 23 Oct 2019
    4.6
    Medium

    CVE-2019-19480

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.

    Published: 23 Oct 2019
    5.3
    Medium

    CVE-2019-7619

    Last Modified: 21 Nov 2024

    Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker could send a specially crafted request and determine if a username exists in the Elasticsearch native realm.

    Published: 23 Oct 2019
    4.3
    Medium

    CVE-2019-18281

    Last Modified: 21 Nov 2024

    An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.

    Published: 23 Oct 2019
    4.4
    Medium

    CVE-2019-5068

    Last Modified: 21 Nov 2024

    An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.

    Published: 23 Oct 2019