CVE-2019-13266
Last Modified: 21 Nov 2024TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.
CVE-2019-13267
Last Modified: 21 Nov 2024TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.
CVE-2019-13268
Last Modified: 21 Nov 2024TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
CVE-2019-13269
Last Modified: 21 Nov 2024Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.
CVE-2019-13270
Last Modified: 21 Nov 2024Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.
CVE-2019-13271
Last Modified: 21 Nov 2024Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
CVE-2019-15698
Last Modified: 21 Nov 2024In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
CVE-2019-13273
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
CVE-2019-13274
Last Modified: 21 Nov 2024In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
CVE-2019-13451
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.
CVE-2019-13452
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.
CVE-2019-13455
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
CVE-2019-13484
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.
CVE-2019-13485
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.
CVE-2019-13486
Last Modified: 21 Nov 2024In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
CVE-2019-14314
Last Modified: 21 Nov 2024A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.
CVE-2019-11457
Last Modified: 21 Nov 2024Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
CVE-2019-15650
Last Modified: 21 Nov 2024The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
CVE-2015-9348
Last Modified: 21 Nov 2024The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
CVE-2017-18592
Last Modified: 21 Nov 2024The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
CVE-2015-9352
Last Modified: 21 Nov 2024The wp-polls plugin before 2.72 for WordPress has SQL injection.
CVE-2019-15660
Last Modified: 21 Nov 2024The wp-members plugin before 3.2.8 for WordPress has CSRF.
CVE-2016-10936
Last Modified: 21 Nov 2024The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
CVE-2017-18591
Last Modified: 23 Apr 2025The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
CVE-2015-9350
Last Modified: 21 Nov 2024The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
CVE-2015-9351
Last Modified: 21 Nov 2024The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.
CVE-2015-9349
Last Modified: 21 Nov 2024The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
CVE-2016-10935
Last Modified: 21 Nov 2024The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
CVE-2018-21006
Last Modified: 21 Nov 2024The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
CVE-2019-15659
Last Modified: 21 Nov 2024The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2018-21005
Last Modified: 21 Nov 2024The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
CVE-2017-18590
Last Modified: 21 Nov 2024The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
CVE-2015-9347
Last Modified: 21 Nov 2024The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
CVE-2014-10395
Last Modified: 21 Nov 2024The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2015-9346
Last Modified: 21 Nov 2024The cp-polls plugin before 1.0.5 for WordPress has XSS.
CVE-2016-10934
Last Modified: 21 Nov 2024The check-email plugin before 0.5.2 for WordPress has XSS.
CVE-2018-17557
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation duplicate of CVE-2018-20986. Notes: All CVE users should reference CVE-2018-20986 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-2019-15649
Last Modified: 21 Nov 2024The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
CVE-2019-15648
Last Modified: 21 Nov 2024The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
CVE-2019-15647
Last Modified: 21 Nov 2024The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
CVE-2018-21004
Last Modified: 21 Nov 2024The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
CVE-2019-15646
Last Modified: 21 Nov 2024The rsvpmaker plugin before 6.2 for WordPress has SQL injection.
CVE-2015-9345
Last Modified: 21 Nov 2024The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.
CVE-2015-9344
Last Modified: 21 Nov 2024The link-log plugin before 2.1 for WordPress has SQL injection.
CVE-2018-21003
Last Modified: 21 Nov 2024The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
CVE-2018-21002
Last Modified: 21 Nov 2024The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2019-15645
Last Modified: 21 Nov 2024The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
CVE-2019-15644
Last Modified: 21 Nov 2024The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
CVE-2015-9343
Last Modified: 21 Nov 2024The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
CVE-2015-9342
Last Modified: 21 Nov 2024The wp-rollback plugin before 1.2.3 for WordPress has XSS.
