CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-9532

    Last Modified: 21 Nov 2024

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-9531

    Last Modified: 21 Nov 2024

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide unauthenticated, shell-like access to the device.

    Published: 10 Oct 2019
    5.5
    Medium

    CVE-2019-9530

    Last Modified: 21 Nov 2024

    The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download any file found in the web root directory.

    Published: 10 Oct 2019
    5.5
    Medium

    CVE-2019-9529

    Last Modified: 21 Nov 2024

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-17386

    Last Modified: 21 Nov 2024

    The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-11527

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-11528

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-15051

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-11526

    Last Modified: 21 Nov 2024

    An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

    Published: 10 Oct 2019
    5.9
    Medium

    CVE-2019-14810

    Last Modified: 21 Nov 2024

    A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially leading to an Out of Memory (OOM) condition that is disruptive to traffic forwarding. Affected EOS versions include: 4.22 release train: 4.22.1F and earlier releases 4.21 release train: 4.21.0F - 4.21.2.3F, 4.21.3F - 4.21.7.1M 4.20 release train: 4.20.14M and earlier releases 4.19 release train: 4.19.12M and earlier releases End of support release trains (4.18 and 4.17)

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-17452

    Last Modified: 21 Nov 2024

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-17453

    Last Modified: 21 Nov 2024

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-17454

    Last Modified: 21 Nov 2024

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.

    Published: 10 Oct 2019
    4.7
    Medium

    CVE-2019-5535

    Last Modified: 21 Nov 2024

    VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-5527

    Last Modified: 21 Nov 2024

    ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2015-9480

    Last Modified: 21 Nov 2024

    The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2015-9479

    Last Modified: 21 Nov 2024

    The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2015-9478

    Last Modified: 21 Nov 2024

    prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9477

    Last Modified: 21 Nov 2024

    The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9476

    Last Modified: 21 Nov 2024

    The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9475

    Last Modified: 21 Nov 2024

    The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9474

    Last Modified: 21 Nov 2024

    The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2015-9473

    Last Modified: 21 Nov 2024

    The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2015-9472

    Last Modified: 21 Nov 2024

    The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2015-9471

    Last Modified: 21 Nov 2024

    The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2015-9463

    Last Modified: 21 Nov 2024

    The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2015-9470

    Last Modified: 21 Nov 2024

    The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.

    Published: 10 Oct 2019
    4.8
    Medium

    CVE-2015-9469

    Last Modified: 21 Nov 2024

    The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2015-9468

    Last Modified: 21 Nov 2024

    The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2015-9467

    Last Modified: 21 Nov 2024

    The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2015-9466

    Last Modified: 21 Nov 2024

    The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9465

    Last Modified: 21 Nov 2024

    The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2015-9464

    Last Modified: 21 Nov 2024

    The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

    Published: 10 Oct 2019
    6.7
    Medium

    CVE-2019-17449

    Last Modified: 21 Nov 2024

    Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges

    Published: 10 Oct 2019
    7.2
    High

    CVE-2015-9462

    Last Modified: 21 Nov 2024

    The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat_id parameter.

    Published: 10 Oct 2019
    7.2
    High

    CVE-2015-9461

    Last Modified: 21 Nov 2024

    The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via the item_id parameter.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2015-9460

    Last Modified: 21 Nov 2024

    The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2015-9459

    Last Modified: 21 Nov 2024

    The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter.

    Published: 10 Oct 2019
    7.2
    High

    CVE-2015-9458

    Last Modified: 21 Nov 2024

    The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.

    Published: 10 Oct 2019
    7.2
    High

    CVE-2015-9457

    Last Modified: 13 Feb 2025

    The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-17320

    Last Modified: 21 Nov 2024

    NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

    Published: 10 Oct 2019
    2.4
    Low

    CVE-2019-4265

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.

    Published: 10 Oct 2019
    6.5
    Medium

    CVE-2019-13929

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used to gain read and write access to the related TeamCenter station. The security vulnerability could be exploited only if the attacker is authenticated. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises the confidentiality of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-10923

    Last Modified: 11 Feb 2025

    An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time synchronization (IRT) of the affected installation.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-13921

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of the software contain a vulnerability that could allow an unauthenticated attacker to trigger a denial-of-service condition. The vulnerability can be triggered if a large HTTP request is sent to the executing service. The security vulnerability could be exploited by an attacker with network access to the affected systems. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the service provided by the software.

    Published: 10 Oct 2019
    4.3
    Medium

    CVE-2019-1357

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-1366

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1307, CVE-2019-1308, CVE-2019-1335.

    Published: 10 Oct 2019
    7.5
    High

    CVE-2019-1371

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

    Published: 10 Oct 2019
    7.8
    High

    CVE-2019-1378

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'.

    Published: 10 Oct 2019
    5.5
    Medium

    CVE-2019-1345

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334.

    Published: 10 Oct 2019