CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-20979

    Last Modified: 21 Nov 2024

    The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2017-18573

    Last Modified: 21 Nov 2024

    The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2016-10921

    Last Modified: 21 Nov 2024

    The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2016-10920

    Last Modified: 21 Nov 2024

    The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2017-18572

    Last Modified: 21 Nov 2024

    The gnucommerce plugin before 1.4.2 for WordPress has XSS.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2012-6716

    Last Modified: 21 Nov 2024

    The events-manager plugin before 5.1.7 for WordPress has XSS via JSON call links.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2013-7480

    Last Modified: 21 Nov 2024

    The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2013-7479

    Last Modified: 21 Nov 2024

    The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2013-7478

    Last Modified: 21 Nov 2024

    The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.

    Published: 22 Aug 2019
    7.5
    High

    CVE-2019-14511

    Last Modified: 21 Nov 2024

    Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2013-7477

    Last Modified: 21 Nov 2024

    The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2016-10919

    Last Modified: 21 Nov 2024

    The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.

    Published: 22 Aug 2019
    8.8
    High

    CVE-2016-10918

    Last Modified: 21 Nov 2024

    The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.

    Published: 22 Aug 2019
    5.4
    Medium

    CVE-2019-15317

    Last Modified: 21 Nov 2024

    The give plugin before 2.4.7 for WordPress has XSS via a donor name.

    Published: 22 Aug 2019
    6.1
    Medium

    CVE-2015-9336

    Last Modified: 21 Nov 2024

    The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2017-18571

    Last Modified: 21 Nov 2024

    The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2016-10917

    Last Modified: 21 Nov 2024

    The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2015-9335

    Last Modified: 21 Nov 2024

    The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

    Published: 22 Aug 2019
    5.4
    Medium

    CVE-2019-15314

    Last Modified: 21 Nov 2024

    tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2015-9333

    Last Modified: 21 Nov 2024

    The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2017-18570

    Last Modified: 21 Nov 2024

    The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2016-10916

    Last Modified: 21 Nov 2024

    The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.

    Published: 22 Aug 2019
    5.5
    Medium

    CVE-2019-18466

    Last Modified: 21 Nov 2024

    An issue was discovered in Podman in libpod before 1.6.0. It resolves a symlink in the host context during a copy operation from the container to the host, because an undesired glob operation occurs. An attacker could create a container image containing particular symlinks that, when copied by a victim user to the host filesystem, may overwrite existing files with others from the host.

    Published: 22 Aug 2019
    9.8
    Critical

    CVE-2019-6177

    Last Modified: 21 Nov 2024

    A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Lenovo Vantage or Lenovo Diagnostics in April 2018.

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-14686

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-14685

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.

    Published: 21 Aug 2019
    8.7
    High

    CVE-2019-5638

    Last Modified: 21 Nov 2024

    Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session is still valid after the password change, potentially allowing the attacker who originally compromised the credential to remain logged in and able to cause further damage.

    Published: 21 Aug 2019
    7
    High

    CVE-2019-15316

    Last Modified: 21 Nov 2024

    Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-15315

    Last Modified: 21 Nov 2024

    Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2019-11603

    Last Modified: 21 Nov 2024

    A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2018-17791

    Last Modified: 21 Nov 2024

    Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side validation" vulnerability where client-side validations are tampered, and inappropriate information is stored on the server side and fetched from the server every time the user visits the D, creating business confusion. In the worst case, all available resources are consumed while processing the data, resulting in unavailability of the service to legitimate users. This occurs because non-editable parameters can be modified by manually editing a disabled form field within the developer options.

    Published: 21 Aug 2019
    5.3
    Medium

    CVE-2019-11602

    Last Modified: 21 Nov 2024

    Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2019-10687

    Last Modified: 21 Nov 2024

    KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2019-11601

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.

    Published: 21 Aug 2019
    5.4
    Medium

    CVE-2019-13476

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to achieve root access via the email list page.

    Published: 21 Aug 2019
    8.8
    High

    CVE-2019-13477

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.

    Published: 21 Aug 2019
    5.3
    Medium

    CVE-2019-13599

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a username is valid by comparing response times.

    Published: 21 Aug 2019
    6.5
    Medium

    CVE-2019-14245

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.

    Published: 21 Aug 2019
    6.5
    Medium

    CVE-2019-14246

    Last Modified: 21 Nov 2024

    In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-14257

    Last Modified: 21 Nov 2024

    pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2019-14258

    Last Modified: 21 Nov 2024

    The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2019-1938

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.

    Published: 21 Aug 2019
    5.9
    Medium

    CVE-2019-1948

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted SSL certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2019-1974

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is due to insufficient request header validation during the authentication process. An attacker could exploit this vulnerability by sending a series of malicious requests to an affected device. An exploit could allow the attacker to gain full administrative access to the affected device.

    Published: 21 Aug 2019
    6.5
    Medium

    CVE-2019-1984

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in an NFVIS file-system command. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying OS.

    Published: 21 Aug 2019
    5.3
    Medium

    CVE-2019-15045

    Last Modified: 21 Nov 2024

    AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality

    Published: 21 Aug 2019
    8.8
    High

    CVE-2019-1907

    Last Modified: 21 Nov 2024

    A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges to gain administrator privileges.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2019-1908

    Last Modified: 21 Nov 2024

    A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A successful exploit could allow the attacker to view sensitive information that belongs to other users. The attacker could then use this information to conduct additional attacks.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2019-1935

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the scpuser account. This includes full read and write access to the system's database.

    Published: 21 Aug 2019
    7.2
    High

    CVE-2019-1936

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of this vulnerability requires privileged access to an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrator privileges and then sending a malicious request to a certain part of the interface.

    Published: 21 Aug 2019