CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-13266

    Last Modified: 21 Nov 2024

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13267

    Last Modified: 21 Nov 2024

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13268

    Last Modified: 21 Nov 2024

    TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13269

    Last Modified: 21 Nov 2024

    Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13270

    Last Modified: 21 Nov 2024

    Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it leaves, the router (following the IGMP protocol) creates an IGMP Membership Query packet with the Group IP and sends it to both the Host and the Guest networks. The data is transferred within the Group IP field, which is completely controlled by the sender.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-13271

    Last Modified: 21 Nov 2024

    Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

    Published: 27 Aug 2019
    4.3
    Medium

    CVE-2019-15698

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13273

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2019-13274

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13451

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13452

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13455

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in acknowledge.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13484

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of   expansion in appfeed.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13485

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-13486

    Last Modified: 21 Nov 2024

    In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-14314

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-11457

    Last Modified: 21 Nov 2024

    Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.

    Published: 27 Aug 2019
    4.3
    Medium

    CVE-2019-15650

    Last Modified: 21 Nov 2024

    The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.

    Published: 27 Aug 2019
    7.5
    High

    CVE-2015-9348

    Last Modified: 21 Nov 2024

    The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.

    Published: 27 Aug 2019
    7.5
    High

    CVE-2017-18592

    Last Modified: 21 Nov 2024

    The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2015-9352

    Last Modified: 21 Nov 2024

    The wp-polls plugin before 2.72 for WordPress has SQL injection.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-15660

    Last Modified: 21 Nov 2024

    The wp-members plugin before 3.2.8 for WordPress has CSRF.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2016-10936

    Last Modified: 21 Nov 2024

    The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2017-18591

    Last Modified: 23 Apr 2025

    The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2015-9350

    Last Modified: 21 Nov 2024

    The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2015-9351

    Last Modified: 21 Nov 2024

    The feed-them-social plugin before 1.7.0 for WordPress has possible shortcode execution in the Facebook Feeds load more button.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2015-9349

    Last Modified: 21 Nov 2024

    The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2016-10935

    Last Modified: 21 Nov 2024

    The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2018-21006

    Last Modified: 21 Nov 2024

    The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-15659

    Last Modified: 21 Nov 2024

    The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2018-21005

    Last Modified: 21 Nov 2024

    The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2017-18590

    Last Modified: 21 Nov 2024

    The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2015-9347

    Last Modified: 21 Nov 2024

    The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2014-10395

    Last Modified: 21 Nov 2024

    The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2015-9346

    Last Modified: 21 Nov 2024

    The cp-polls plugin before 1.0.5 for WordPress has XSS.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2016-10934

    Last Modified: 21 Nov 2024

    The check-email plugin before 0.5.2 for WordPress has XSS.

    Published: 27 Aug 2019
    —
    Unknown

    CVE-2018-17557

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-20986. Reason: This candidate is a reservation duplicate of CVE-2018-20986. Notes: All CVE users should reference CVE-2018-20986 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-15649

    Last Modified: 21 Nov 2024

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

    Published: 27 Aug 2019
    6.5
    Medium

    CVE-2019-15648

    Last Modified: 21 Nov 2024

    The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-15647

    Last Modified: 21 Nov 2024

    The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2018-21004

    Last Modified: 21 Nov 2024

    The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2019-15646

    Last Modified: 21 Nov 2024

    The rsvpmaker plugin before 6.2 for WordPress has SQL injection.

    Published: 27 Aug 2019
    7.5
    High

    CVE-2015-9345

    Last Modified: 21 Nov 2024

    The link-log plugin before 2.0 for WordPress has HTTP Response Splitting.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2015-9344

    Last Modified: 21 Nov 2024

    The link-log plugin before 2.1 for WordPress has SQL injection.

    Published: 27 Aug 2019
    9.8
    Critical

    CVE-2018-21003

    Last Modified: 21 Nov 2024

    The buddyforms plugin before 2.2.8 for WordPress has SQL injection.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2018-21002

    Last Modified: 21 Nov 2024

    The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2019-15645

    Last Modified: 21 Nov 2024

    The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2019-15644

    Last Modified: 21 Nov 2024

    The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.

    Published: 27 Aug 2019
    8.8
    High

    CVE-2015-9343

    Last Modified: 21 Nov 2024

    The wp-rollback plugin before 1.2.3 for WordPress has CSRF.

    Published: 27 Aug 2019
    6.1
    Medium

    CVE-2015-9342

    Last Modified: 21 Nov 2024

    The wp-rollback plugin before 1.2.3 for WordPress has XSS.

    Published: 27 Aug 2019