CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-5033

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds read vulnerability exists in the Number record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds read, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 21 Aug 2019
    5.5
    Medium

    CVE-2019-3634

    Last Modified: 21 Nov 2024

    Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory.

    Published: 21 Aug 2019
    5.5
    Medium

    CVE-2019-3633

    Last Modified: 21 Nov 2024

    Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18560

    Last Modified: 21 Nov 2024

    The content-audit plugin before 1.9.2 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18558

    Last Modified: 21 Nov 2024

    The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18557

    Last Modified: 21 Nov 2024

    The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18556

    Last Modified: 21 Nov 2024

    The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18555

    Last Modified: 21 Nov 2024

    The booking-sms plugin before 1.1.0 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18554

    Last Modified: 21 Nov 2024

    The analytics-tracker plugin before 1.1.1 for WordPress has XSS via a search event.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18553

    Last Modified: 21 Nov 2024

    The ad-buttons plugin before 2.3.2 for WordPress has XSS.

    Published: 21 Aug 2019
    8.8
    High

    CVE-2016-10903

    Last Modified: 21 Nov 2024

    The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.

    Published: 21 Aug 2019
    8.8
    High

    CVE-2016-10902

    Last Modified: 21 Nov 2024

    The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2016-10909

    Last Modified: 21 Nov 2024

    The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10901

    Last Modified: 21 Nov 2024

    The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10908

    Last Modified: 21 Nov 2024

    The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10900

    Last Modified: 21 Nov 2024

    The uji-countdown plugin before 2.0.7 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2019-15112

    Last Modified: 21 Nov 2024

    The wp-slimstat plugin before 4.8.1 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18565

    Last Modified: 21 Nov 2024

    The updater plugin before 1.35 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    9.8
    Critical

    CVE-2019-15111

    Last Modified: 21 Nov 2024

    The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2019-15110

    Last Modified: 21 Nov 2024

    The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18540

    Last Modified: 21 Nov 2024

    The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18539

    Last Modified: 21 Nov 2024

    The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18538

    Last Modified: 21 Nov 2024

    The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18537

    Last Modified: 21 Nov 2024

    The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10898

    Last Modified: 21 Nov 2024

    The total-security plugin before 3.4.1 for WordPress has XSS.

    Published: 21 Aug 2019
    5.3
    Medium

    CVE-2016-10899

    Last Modified: 21 Nov 2024

    The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2019-15109

    Last Modified: 21 Nov 2024

    The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2015-9321

    Last Modified: 21 Nov 2024

    The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18534

    Last Modified: 21 Nov 2024

    The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10897

    Last Modified: 21 Nov 2024

    The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2017-18536

    Last Modified: 23 Jan 2026

    The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.

    Published: 21 Aug 2019
    6.1
    Medium

    CVE-2016-10896

    Last Modified: 21 Nov 2024

    The seo-redirection plugin before 4.3 for WordPress has stored XSS.

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-15296

    Last Modified: 21 Nov 2024

    An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow is later performed via getdword_n(&ld->start[words], ld->bytes_left).

    Published: 21 Aug 2019
    7.8
    High

    CVE-2019-15293

    Last Modified: 21 Nov 2024

    An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.

    Published: 21 Aug 2019
    2.4
    Low

    CVE-2019-19533

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.

    Published: 21 Aug 2019
    6.5
    Medium

    CVE-2019-12746

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.

    Published: 21 Aug 2019
    4.7
    Medium

    CVE-2019-15292

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.

    Published: 21 Aug 2019
    6.5
    Medium

    CVE-2019-13458

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.

    Published: 21 Aug 2019
    7.5
    High

    CVE-2019-5036

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to trigger this vulnerability.

    Published: 20 Aug 2019
    9
    Critical

    CVE-2019-5035

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.

    Published: 20 Aug 2019
    5.3
    Medium

    CVE-2019-5034

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-10960

    Last Modified: 21 Nov 2024

    Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-5040

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-5037

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-5039

    Last Modified: 21 Nov 2024

    An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-5038

    Last Modified: 21 Nov 2024

    An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8106

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8105

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8104

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8103

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019