CVE-2019-4117
Last Modified: 21 Nov 2024IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.
CVE-2019-4049
Last Modified: 21 Nov 2024IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service. IBM X-Force ID: 156398.
CVE-2019-7594
Last Modified: 21 Nov 2024Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
CVE-2019-7593
Last Modified: 21 Nov 2024Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
CVE-2019-10745
Last Modified: 21 Nov 2024assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
CVE-2019-3968
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
CVE-2019-3967
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.
CVE-2019-3966
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2019-3965
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2019-3964
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2019-3963
Last Modified: 21 Nov 2024In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2019-11209
Last Modified: 21 Nov 2024The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls. This issue affects TIBCO FTL Community Edition 6.0.0; 6.0.1; 6.1.0, TIBCO FTL Developer Edition 6.0.1; 6.1.0, and TIBCO FTL Enterprise Edition 6.0.0; 6.0.1; 6.1.0.
CVE-2018-18056
Last Modified: 21 Nov 2024An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only-Memory (XOM) implementation prevents code read-outs on protected memory by generating bus faults. However, single-stepping and using breakpoints is allowed in XOM-protected flash memory. As a consequence, it is possible to execute single instructions with arbitrary system states (e.g., registers, status flags, and SRAM content) and observe the state changes produced by the unknown instruction. An attacker could exploit this vulnerability by executing protected and unknown instructions with specific system states and observing the state changes. Based on the gathered information, it is possible to reverse-engineer the executed instructions. The processor acts as a kind of "instruction oracle."
CVE-2017-18533
Last Modified: 21 Nov 2024The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.
CVE-2017-18532
Last Modified: 21 Nov 2024The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
CVE-2017-18531
Last Modified: 21 Nov 2024The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.
CVE-2017-18530
Last Modified: 21 Nov 2024The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.
CVE-2017-18529
Last Modified: 21 Nov 2024The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.
CVE-2017-18528
Last Modified: 21 Nov 2024The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.
CVE-2015-9320
Last Modified: 21 Nov 2024The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
CVE-2017-18527
Last Modified: 21 Nov 2024The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.
CVE-2016-10895
Last Modified: 21 Nov 2024The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
CVE-2017-18526
Last Modified: 21 Nov 2024The moreads-se plugin before 1.4.7 for WordPress has XSS.
CVE-2015-9319
Last Modified: 21 Nov 2024The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
CVE-2017-18524
Last Modified: 16 Jul 2025The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.
CVE-2017-18519
Last Modified: 21 Nov 2024The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
CVE-2017-18523
Last Modified: 21 Nov 2024The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
CVE-2017-18522
Last Modified: 21 Nov 2024The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
CVE-2016-10892
Last Modified: 21 Nov 2024The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
CVE-2017-18566
Last Modified: 21 Nov 2024The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.
CVE-2017-18518
Last Modified: 21 Nov 2024The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
CVE-2018-20978
Last Modified: 21 Nov 2024The wp-all-import plugin before 3.4.7 for WordPress has XSS.
CVE-2017-18567
Last Modified: 21 Nov 2024The wp-all-import plugin before 3.4.6 for WordPress has XSS.
CVE-2015-9329
Last Modified: 21 Nov 2024The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.
CVE-2015-9330
Last Modified: 21 Nov 2024The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
CVE-2015-9331
Last Modified: 21 Nov 2024The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
CVE-2016-10913
Last Modified: 21 Nov 2024The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
CVE-2016-10914
Last Modified: 21 Nov 2024The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
CVE-2019-15238
Last Modified: 21 Nov 2024The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
CVE-2017-18568
Last Modified: 21 Nov 2024The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
CVE-2017-18569
Last Modified: 21 Nov 2024The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
CVE-2016-10915
Last Modified: 21 Nov 2024The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
CVE-2017-18520
Last Modified: 21 Nov 2024The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
CVE-2015-9332
Last Modified: 21 Nov 2024The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
CVE-2011-5328
Last Modified: 21 Nov 2024The user-access-manager plugin before 1.2 for WordPress has CSRF.
CVE-2014-10381
Last Modified: 21 Nov 2024The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
CVE-2015-9318
Last Modified: 21 Nov 2024The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
CVE-2017-18517
Last Modified: 21 Nov 2024The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2015-9317
Last Modified: 21 Nov 2024The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.
CVE-2019-14687
Last Modified: 21 Nov 2024A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.
