CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2019-6649

    Last Modified: 21 Nov 2024

    F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 and Enterprise Manager 3.1.1 may expose sensitive information and allow the system configuration to be modified when using non-default ConfigSync settings.

    Published: 20 Sept 2019
    9.1
    Critical

    CVE-2019-6650

    Last Modified: 21 Nov 2024

    F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 may expose sensitive information and allow the system configuration to be modified when using non-default settings.

    Published: 20 Sept 2019
    7.5
    High

    CVE-2014-10397

    Last Modified: 21 Nov 2024

    The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.

    Published: 20 Sept 2019
    7.5
    High

    CVE-2014-10396

    Last Modified: 21 Nov 2024

    The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.

    Published: 20 Sept 2019
    7.5
    High

    CVE-2015-9406

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.

    Published: 20 Sept 2019
    7.5
    High

    CVE-2019-15138

    Last Modified: 21 Nov 2024

    The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2019-11280

    Last Modified: 21 Nov 2024

    Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.

    Published: 20 Sept 2019
    4.9
    Medium

    CVE-2019-11327

    Last Modified: 21 Nov 2024

    An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system.

    Published: 20 Sept 2019
    8.6
    High

    CVE-2019-16645

    Last Modified: 21 Nov 2024

    An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2019-11326

    Last Modified: 21 Nov 2024

    An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to login. Once logged in as a guest, an attacker can browse a URL to read the password of the administrative user. The same procedure allows a regular user to gain administrative privileges. The guest login is possible in the default configuration.

    Published: 20 Sept 2019
    6.5
    Medium

    CVE-2018-17789

    Last Modified: 21 Nov 2024

    Prospecta Master Data Online (MDO) allows CSRF.

    Published: 20 Sept 2019
    9.6
    Critical

    CVE-2019-5521

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6) and Fusion (11.x before 11.0.3 and 10.x before 10.1.6) contain an out-of-bounds read vulnerability in the pixel shader functionality. Successful exploitation of this issue may lead to information disclosure or may allow attackers with normal user privileges to create a denial-of-service condition on the host. Exploitation of this issue require an attacker to have access to a virtual machine with 3D graphics enabled. It is not enabled by default on ESXi and is enabled by default on Workstation and Fusion.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2018-11200

    Last Modified: 21 Nov 2024

    An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.

    Published: 20 Sept 2019
    7.5
    High

    CVE-2019-4565

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166626.

    Published: 20 Sept 2019
    5.3
    Medium

    CVE-2019-4505

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensitive information, caused by sending a specially-crafted URL. This can lead the attacker to view any file in a certain directory. IBM X-Force ID: 164364.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2019-16534

    Last Modified: 21 Nov 2024

    On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2019-16533

    Last Modified: 21 Nov 2024

    On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product.

    Published: 20 Sept 2019
    6.5
    Medium

    CVE-2015-9408

    Last Modified: 21 Nov 2024

    The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9407

    Last Modified: 21 Nov 2024

    The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.

    Published: 20 Sept 2019
    9.8
    Critical

    CVE-2019-16644

    Last Modified: 21 Nov 2024

    App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9405

    Last Modified: 21 Nov 2024

    The wp-piwik plugin before 1.0.5 for WordPress has XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9404

    Last Modified: 21 Nov 2024

    The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9403

    Last Modified: 21 Nov 2024

    The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2015-9402

    Last Modified: 21 Nov 2024

    The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.

    Published: 20 Sept 2019
    4.8
    Medium

    CVE-2015-9401

    Last Modified: 21 Nov 2024

    The websimon-tables plugin through 1.3.4 for WordPress has wp-admin/tools.php edit_style id XSS.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2015-9400

    Last Modified: 21 Nov 2024

    The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.

    Published: 20 Sept 2019
    7.2
    High

    CVE-2015-9399

    Last Modified: 21 Nov 2024

    The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2015-9398

    Last Modified: 21 Nov 2024

    The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2015-9397

    Last Modified: 21 Nov 2024

    The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php deletegc XSS.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2019-16643

    Last Modified: 21 Nov 2024

    An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9396

    Last Modified: 21 Nov 2024

    The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file= XSS.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2015-9395

    Last Modified: 21 Nov 2024

    The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

    Published: 20 Sept 2019
    8.8
    High

    CVE-2015-9394

    Last Modified: 21 Nov 2024

    The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2015-9393

    Last Modified: 21 Nov 2024

    The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_desc parameter.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2015-9392

    Last Modified: 21 Nov 2024

    The users-ultra plugin before 1.5.63 for WordPress has XSS via the p_name parameter.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9391

    Last Modified: 21 Nov 2024

    The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.

    Published: 20 Sept 2019
    4.3
    Medium

    CVE-2015-9390

    Last Modified: 21 Nov 2024

    The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2015-9389

    Last Modified: 21 Nov 2024

    The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via a quiz name.

    Published: 20 Sept 2019
    6.5
    Medium

    CVE-2015-9388

    Last Modified: 21 Nov 2024

    The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9386

    Last Modified: 21 Nov 2024

    The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.

    Published: 20 Sept 2019
    6.5
    Medium

    CVE-2015-9387

    Last Modified: 21 Nov 2024

    The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9385

    Last Modified: 21 Nov 2024

    The quotes-and-tips plugin before 1.20 for WordPress has XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2015-9384

    Last Modified: 21 Nov 2024

    The relevant plugin before 1.0.8 for WordPress has XSS.

    Published: 20 Sept 2019
    6.1
    Medium

    CVE-2016-11013

    Last Modified: 21 Nov 2024

    The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.

    Published: 20 Sept 2019
    5.4
    Medium

    CVE-2016-11012

    Last Modified: 21 Nov 2024

    The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.

    Published: 20 Sept 2019
    6.5
    Medium

    CVE-2016-11011

    Last Modified: 21 Nov 2024

    The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

    Published: 20 Sept 2019
    5.3
    Medium

    CVE-2016-11010

    Last Modified: 21 Nov 2024

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

    Published: 20 Sept 2019
    5.3
    Medium

    CVE-2016-11009

    Last Modified: 21 Nov 2024

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

    Published: 20 Sept 2019
    5.3
    Medium

    CVE-2016-11008

    Last Modified: 21 Nov 2024

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

    Published: 20 Sept 2019
    5.3
    Medium

    CVE-2016-11007

    Last Modified: 21 Nov 2024

    The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

    Published: 20 Sept 2019