CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-14273

    Last Modified: 21 Nov 2024

    In SilverStripe assets 4.0, there is broken access control on files.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2019-16904

    Last Modified: 21 Nov 2024

    TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-16903

    Last Modified: 21 Nov 2024

    Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9441

    Last Modified: 21 Nov 2024

    The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9442

    Last Modified: 21 Nov 2024

    The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9443

    Last Modified: 21 Nov 2024

    The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2015-9444

    Last Modified: 21 Nov 2024

    The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/ PATH_SELF.

    Published: 26 Sept 2019
    8.8
    High

    CVE-2015-9445

    Last Modified: 21 Nov 2024

    The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.

    Published: 26 Sept 2019
    8.8
    High

    CVE-2015-9446

    Last Modified: 21 Nov 2024

    The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9447

    Last Modified: 21 Nov 2024

    The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.

    Published: 26 Sept 2019
    8.8
    High

    CVE-2015-9448

    Last Modified: 21 Nov 2024

    The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9440

    Last Modified: 21 Nov 2024

    The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.

    Published: 26 Sept 2019
    4.8
    Medium

    CVE-2015-9439

    Last Modified: 21 Nov 2024

    The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2015-9438

    Last Modified: 21 Nov 2024

    The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9437

    Last Modified: 27 Nov 2024

    The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2015-9436

    Last Modified: 27 Nov 2024

    The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter.

    Published: 26 Sept 2019
    9.8
    Critical

    CVE-2015-9435

    Last Modified: 21 Nov 2024

    The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9434

    Last Modified: 21 Nov 2024

    The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9433

    Last Modified: 21 Nov 2024

    The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9432

    Last Modified: 21 Nov 2024

    The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9431

    Last Modified: 21 Nov 2024

    The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-16899

    Last Modified: 21 Nov 2024

    In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-16900

    Last Modified: 21 Nov 2024

    Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-16901

    Last Modified: 21 Nov 2024

    Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

    Published: 26 Sept 2019
    7.2
    High

    CVE-2015-9449

    Last Modified: 21 Nov 2024

    The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2015-9430

    Last Modified: 21 Nov 2024

    The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9429

    Last Modified: 21 Nov 2024

    The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9428

    Last Modified: 21 Nov 2024

    The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9427

    Last Modified: 21 Nov 2024

    The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.

    Published: 26 Sept 2019
    4.6
    Medium

    CVE-2015-9426

    Last Modified: 21 Nov 2024

    The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2015-9425

    Last Modified: 21 Nov 2024

    The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9424

    Last Modified: 21 Nov 2024

    The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2015-9423

    Last Modified: 21 Nov 2024

    The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9422

    Last Modified: 21 Nov 2024

    The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2015-9421

    Last Modified: 21 Nov 2024

    The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2015-9420

    Last Modified: 21 Nov 2024

    The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2015-9419

    Last Modified: 21 Nov 2024

    The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-16910

    Last Modified: 5 Jun 2026

    Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-14853

    Last Modified: 21 Nov 2024

    An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-16869

    Last Modified: 7 Jul 2025

    Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-14844

    Last Modified: 21 Nov 2024

    A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.

    Published: 26 Sept 2019
    5.9
    Medium

    CVE-2019-19076

    Last Modified: 21 Nov 2024

    A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted

    Published: 26 Sept 2019
    4.3
    Medium

    CVE-2015-9418

    Last Modified: 21 Nov 2024

    The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.

    Published: 25 Sept 2019
    6.5
    Medium

    CVE-2015-9417

    Last Modified: 21 Nov 2024

    The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.

    Published: 25 Sept 2019
    6.1
    Medium

    CVE-2015-9416

    Last Modified: 21 Nov 2024

    The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.

    Published: 25 Sept 2019
    7.5
    High

    CVE-2015-9415

    Last Modified: 21 Nov 2024

    The bj-lazy-load plugin before 1.0 for WordPress has Remote File Inclusion.

    Published: 25 Sept 2019
    6.1
    Medium

    CVE-2015-9414

    Last Modified: 21 Nov 2024

    The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.

    Published: 25 Sept 2019
    6.5
    Medium

    CVE-2015-9413

    Last Modified: 21 Nov 2024

    The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.

    Published: 25 Sept 2019
    6.1
    Medium

    CVE-2015-9412

    Last Modified: 21 Nov 2024

    The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.

    Published: 25 Sept 2019
    6.1
    Medium

    CVE-2015-9411

    Last Modified: 21 Nov 2024

    The Postmatic plugin before 1.4.6 for WordPress has XSS.

    Published: 25 Sept 2019