CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-15514

    Last Modified: 21 Nov 2024

    The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction of a region's assigned phone numbers.

    Published: 23 Aug 2019
    7.5
    High

    CVE-2019-15513

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.

    Published: 23 Aug 2019
    6.5
    Medium

    CVE-2019-15507

    Last Modified: 21 Nov 2024

    In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.7. The fix was back-ported to LTS 2019.6.7 as well as LTS 2019.3.8.

    Published: 23 Aug 2019
    6.5
    Medium

    CVE-2019-15508

    Last Modified: 21 Nov 2024

    In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 5.0.1. The fix was back-ported to 4.0.7.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-15499

    Last Modified: 21 Nov 2024

    CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-15498

    Last Modified: 21 Nov 2024

    cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15505

    Last Modified: 21 Nov 2024

    drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).

    Published: 23 Aug 2019
    8.8
    High

    CVE-2019-13423

    Last Modified: 21 Nov 2024

    Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true: a) Kibana is configured to use Single-Sign-On as authentication method, one of Kerberos, JWT, Proxy, Client certificate. b) The kibanaserver user is configured to use HTTP Basic as the authentication method. c) Search Guard is configured to use an SSO authentication domain and HTTP Basic at the same time

    Published: 23 Aug 2019
    9.8
    Critical

    CVE-2019-15504

    Last Modified: 21 Nov 2024

    drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2019-13422

    Last Modified: 21 Nov 2024

    Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.

    Published: 23 Aug 2019
    4.9
    Medium

    CVE-2019-13421

    Last Modified: 21 Nov 2024

    Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

    Published: 23 Aug 2019
    5.5
    Medium

    CVE-2019-12400

    Last Modified: 21 Nov 2024

    In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this implementation might be cached and re-used by Apache Santuario - XML Security for Java, leading to potential security flaws when validating signed documents, etc. The vulnerability affects Apache Santuario - XML Security for Java 2.0.x releases from 2.0.3 and all 2.1.x releases before 2.1.4.

    Published: 23 Aug 2019
    6.1
    Medium

    CVE-2014-10393

    Last Modified: 21 Nov 2024

    The cforms2 plugin before 10.5 for WordPress has XSS.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2015-9334

    Last Modified: 21 Nov 2024

    The email-newsletter plugin through 20.15 for WordPress has SQL injection.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2017-18578

    Last Modified: 21 Nov 2024

    The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2017-18579

    Last Modified: 21 Nov 2024

    The corner-ad plugin before 1.0.8 for WordPress has XSS.

    Published: 22 Aug 2019
    4.3
    Medium

    CVE-2014-10382

    Last Modified: 21 Nov 2024

    The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2016-10928

    Last Modified: 21 Nov 2024

    The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

    Published: 22 Aug 2019
    5.3
    Medium

    CVE-2016-10929

    Last Modified: 21 Nov 2024

    The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.

    Published: 22 Aug 2019
    5.4
    Medium

    CVE-2018-20986

    Last Modified: 21 Nov 2024

    The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.

    Published: 22 Aug 2019
    8.1
    High

    CVE-2017-18585

    Last Modified: 21 Nov 2024

    The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2013-7483

    Last Modified: 21 Nov 2024

    The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2019-15325

    Last Modified: 21 Nov 2024

    In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/ptrace_scope to 1, which might increase risk because of the appearance that a protection mechanism is present when actually it is not.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2019-15326

    Last Modified: 21 Nov 2024

    The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2019-15327

    Last Modified: 21 Nov 2024

    The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2019-15328

    Last Modified: 21 Nov 2024

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

    Published: 22 Aug 2019
    8.8
    High

    CVE-2019-15329

    Last Modified: 21 Nov 2024

    The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2014-10386

    Last Modified: 21 Nov 2024

    The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2018-20987

    Last Modified: 21 Nov 2024

    The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2015-9338

    Last Modified: 21 Nov 2024

    The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2015-9339

    Last Modified: 21 Nov 2024

    The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2015-9340

    Last Modified: 21 Nov 2024

    The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2015-9341

    Last Modified: 21 Nov 2024

    The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2019-15330

    Last Modified: 21 Nov 2024

    The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2019-15331

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2016-10930

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

    Published: 22 Aug 2019
    8.8
    High

    CVE-2019-15060

    Last Modified: 21 Nov 2024

    The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2014-10387

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

    Published: 22 Aug 2019
    5.3
    Medium

    CVE-2014-10388

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2014-10389

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

    Published: 22 Aug 2019
    9.1
    Critical

    CVE-2014-10390

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2014-10391

    Last Modified: 21 Nov 2024

    The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2018-20988

    Last Modified: 21 Nov 2024

    The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2014-10392

    Last Modified: 21 Nov 2024

    The cforms2 plugin before 10.2 for WordPress has XSS.

    Published: 22 Aug 2019
    9.1
    Critical

    CVE-2017-18586

    Last Modified: 21 Nov 2024

    The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2014-10394

    Last Modified: 21 Nov 2024

    The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

    Published: 22 Aug 2019
    5.4
    Medium

    CVE-2019-12386

    Last Modified: 21 Nov 2024

    An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

    Published: 22 Aug 2019
    8.8
    High

    CVE-2019-12385

    Last Modified: 21 Nov 2024

    An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword functionality.

    Published: 22 Aug 2019
    5.4
    Medium

    CVE-2019-14469

    Last Modified: 21 Nov 2024

    In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.

    Published: 22 Aug 2019
    7.2
    High

    CVE-2019-7617

    Last Modified: 21 Nov 2024

    When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.

    Published: 22 Aug 2019