CVE-2019-14751
Last Modified: 21 Nov 2024NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.
CVE-2019-9155
Last Modified: 21 Nov 2024A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
CVE-2019-9154
Last Modified: 21 Nov 2024Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
CVE-2019-9153
Last Modified: 21 Nov 2024Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
CVE-2019-11031
Last Modified: 21 Nov 2024Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges.
CVE-2019-11030
Last Modified: 21 Nov 2024Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serialized object) may be executed with SYSTEM privileges. The attacker must properly encrypt the object; however, the hardcoded keys are available.
CVE-2019-11029
Last Modified: 21 Nov 2024Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of interesting system files and download them without previous authentication. This includes SAM-database backups, Web.config files, etc. and might cause a serious impact on confidentiality.
CVE-2019-11013
Last Modified: 21 Nov 2024Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the restricted directory on the remote server.
CVE-2018-18573
Last Modified: 21 Nov 2024osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
CVE-2018-18572
Last Modified: 21 Nov 2024osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Because of this filter, script files with certain PHP-related extensions (such as .phtml and .php5) didn't execute in the application. But this filter didn't prevent the '.pht' extension. Thus, remote authenticated administrators can upload '.pht' files for arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.
CVE-2019-5635
Last Modified: 21 Nov 2024A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates over the network to an MQTT broker without using encryption. This exposed the default username and password used to authenticate to the MQTT broker. This issue affects Hickory Smart Ethernet Bridge, model number H077646. The firmware does not appear to contain versioning information.
CVE-2019-5634
Last Modified: 21 Nov 2024An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.
CVE-2019-5633
Last Modified: 21 Nov 2024An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions.
CVE-2019-5632
Last Modified: 21 Nov 2024An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.
CVE-2017-18584
Last Modified: 21 Nov 2024The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.
CVE-2017-18583
Last Modified: 21 Nov 2024The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
CVE-2015-9337
Last Modified: 21 Nov 2024The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJAX.
CVE-2019-15324
Last Modified: 21 Nov 2024The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
CVE-2019-15323
Last Modified: 21 Nov 2024The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
CVE-2017-18582
Last Modified: 21 Nov 2024The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.
CVE-2017-18581
Last Modified: 21 Nov 2024The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.
CVE-2018-20985
Last Modified: 21 Nov 2024The wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.
CVE-2017-18580
Last Modified: 21 Nov 2024The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.
CVE-2019-15322
Last Modified: 21 Nov 2024The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
CVE-2018-20984
Last Modified: 21 Nov 2024The patreon-connect plugin before 1.2.2 for WordPress has Object Injection.
CVE-2019-15321
Last Modified: 21 Nov 2024The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
CVE-2019-15320
Last Modified: 21 Nov 2024The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
CVE-2019-15319
Last Modified: 21 Nov 2024The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
CVE-2016-10927
Last Modified: 21 Nov 2024The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10926
Last Modified: 21 Nov 2024The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
CVE-2014-10385
Last Modified: 21 Nov 2024The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.
CVE-2014-10384
Last Modified: 21 Nov 2024The memphis-documents-library plugin before 3.0 for WordPress has Local File Inclusion.
CVE-2014-10383
Last Modified: 21 Nov 2024The memphis-documents-library plugin before 3.0 for WordPress has Remote File Inclusion.
CVE-2018-20983
Last Modified: 21 Nov 2024The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.
CVE-2008-7321
Last Modified: 21 Nov 2024The tubepress plugin before 1.6.5 for WordPress has XSS.
CVE-2013-7482
Last Modified: 21 Nov 2024The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
CVE-2016-10925
Last Modified: 21 Nov 2024The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
CVE-2017-18577
Last Modified: 27 Jan 2026The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
CVE-2016-10924
Last Modified: 21 Nov 2024The ebook-download plugin before 1.2 for WordPress has directory traversal.
CVE-2017-18576
Last Modified: 21 Nov 2024The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.
CVE-2016-10923
Last Modified: 21 Nov 2024The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2016-10922
Last Modified: 21 Nov 2024The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2017-18575
Last Modified: 21 Nov 2024The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
CVE-2018-20982
Last Modified: 21 Nov 2024The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library assistant admin submenu screens.
CVE-2013-7481
Last Modified: 21 Nov 2024The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
CVE-2019-15318
Last Modified: 21 Nov 2024The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
CVE-2017-18574
Last Modified: 21 Nov 2024The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.
CVE-2018-20981
Last Modified: 21 Nov 2024The ninja-forms plugin before 3.3.9 for WordPress has insufficient restrictions on submission-data retrieval during Export Personal Data requests.
CVE-2009-5158
Last Modified: 21 Nov 2024The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
CVE-2018-20980
Last Modified: 21 Nov 2024The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
