CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-9375

    Last Modified: 21 Nov 2024

    Table Rate Shipping Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9374

    Last Modified: 21 Nov 2024

    Stripe Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9373

    Last Modified: 21 Nov 2024

    PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9372

    Last Modified: 21 Nov 2024

    Membership Add-on for iThemes Exchange before 1.3.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9371

    Last Modified: 21 Nov 2024

    Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9370

    Last Modified: 21 Nov 2024

    Invoices Add-on for iThemes Exchange before 1.4.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9369

    Last Modified: 21 Nov 2024

    Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9368

    Last Modified: 21 Nov 2024

    Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9367

    Last Modified: 21 Nov 2024

    Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14812

    Last Modified: 21 Nov 2024

    A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

    Published: 28 Aug 2019
    9.8
    Critical

    CVE-2019-14813

    Last Modified: 21 Nov 2024

    A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

    Published: 28 Aug 2019
    9.8
    Critical

    CVE-2019-11500

    Last Modified: 21 Nov 2024

    In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14811

    Last Modified: 21 Nov 2024

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14817

    Last Modified: 21 Nov 2024

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9366

    Last Modified: 21 Nov 2024

    Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9365

    Last Modified: 21 Nov 2024

    Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9364

    Last Modified: 21 Nov 2024

    2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9363

    Last Modified: 21 Nov 2024

    iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9362

    Last Modified: 21 Nov 2024

    The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9361

    Last Modified: 21 Nov 2024

    The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9360

    Last Modified: 21 Nov 2024

    The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2019-15713

    Last Modified: 21 Nov 2024

    The my-calendar plugin before 3.1.10 for WordPress has XSS.

    Published: 28 Aug 2019
    5.3
    Medium

    CVE-2019-15714

    Last Modified: 21 Nov 2024

    cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9358

    Last Modified: 21 Nov 2024

    The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9357

    Last Modified: 21 Nov 2024

    The akismet plugin before 3.1.5 for WordPress has XSS.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9356

    Last Modified: 21 Nov 2024

    The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue than CVE-2014-9460.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2017-18593

    Last Modified: 21 Nov 2024

    The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2015-9355

    Last Modified: 21 Nov 2024

    The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.

    Published: 28 Aug 2019
    9.8
    Critical

    CVE-2012-6719

    Last Modified: 21 Nov 2024

    The sharebar plugin before 1.2.2 for WordPress has SQL injection.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2012-6718

    Last Modified: 21 Nov 2024

    The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2011-5329

    Last Modified: 21 Nov 2024

    The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2012-6717

    Last Modified: 21 Nov 2024

    The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.

    Published: 28 Aug 2019
    4.8
    Medium

    CVE-2015-9354

    Last Modified: 25 Feb 2026

    The gigpress plugin before 2.3.11 for WordPress has XSS.

    Published: 28 Aug 2019
    7.2
    High

    CVE-2015-9353

    Last Modified: 21 Nov 2024

    The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.

    Published: 28 Aug 2019
    9.8
    Critical

    CVE-2019-15294

    Last Modified: 21 Nov 2024

    An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14815

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14814

    Last Modified: 21 Nov 2024

    There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-14816

    Last Modified: 21 Nov 2024

    There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.

    Published: 28 Aug 2019
    6.1
    Medium

    CVE-2019-10219

    Last Modified: 25 Aug 2026

    A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

    Published: 28 Aug 2019
    9.1
    Critical

    CVE-2019-15753

    Last Modified: 21 Nov 2024

    In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected. This occurs in PyRoute2.add() in internal/command/ip/linux/impl_pyroute2.py.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-16905

    Last Modified: 23 Apr 2025

    OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

    Published: 28 Aug 2019
    8.8
    High

    CVE-2019-10384

    Last Modified: 21 Nov 2024

    Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

    Published: 28 Aug 2019
    7.8
    High

    CVE-2019-15767

    Last Modified: 21 Nov 2024

    In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.

    Published: 28 Aug 2019
    4.8
    Medium

    CVE-2019-10383

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.

    Published: 28 Aug 2019
    7.5
    High

    CVE-2019-15702

    Last Modified: 21 Nov 2024

    In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an unknown zero-length option.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-15701

    Last Modified: 21 Nov 2024

    components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing JavaScript in its name.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2019-15700

    Last Modified: 21 Nov 2024

    public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13263

    Last Modified: 21 Nov 2024

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13264

    Last Modified: 21 Nov 2024

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13265

    Last Modified: 21 Nov 2024

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

    Published: 27 Aug 2019