CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-4117

    Last Modified: 21 Nov 2024

    IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.

    Published: 20 Aug 2019
    5.5
    Medium

    CVE-2019-4049

    Last Modified: 21 Nov 2024

    IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service. IBM X-Force ID: 156398.

    Published: 20 Aug 2019
    6.8
    Medium

    CVE-2019-7594

    Last Modified: 21 Nov 2024

    Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).

    Published: 20 Aug 2019
    6.8
    Medium

    CVE-2019-7593

    Last Modified: 21 Nov 2024

    Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-10745

    Last Modified: 21 Nov 2024

    assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-3968

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.

    Published: 20 Aug 2019
    6.5
    Medium

    CVE-2019-3967

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-3966

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-3965

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-3964

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2019-3963

    Last Modified: 21 Nov 2024

    In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-11209

    Last Modified: 21 Nov 2024

    The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIBCO FTL Enterprise Edition contains a vulnerability that theoretically fails to properly enforce access controls. This issue affects TIBCO FTL Community Edition 6.0.0; 6.0.1; 6.1.0, TIBCO FTL Developer Edition 6.0.1; 6.1.0, and TIBCO FTL Enterprise Edition 6.0.0; 6.0.1; 6.1.0.

    Published: 20 Aug 2019
    4.6
    Medium

    CVE-2018-18056

    Last Modified: 21 Nov 2024

    An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only-Memory (XOM) implementation prevents code read-outs on protected memory by generating bus faults. However, single-stepping and using breakpoints is allowed in XOM-protected flash memory. As a consequence, it is possible to execute single instructions with arbitrary system states (e.g., registers, status flags, and SRAM content) and observe the state changes produced by the unknown instruction. An attacker could exploit this vulnerability by executing protected and unknown instructions with specific system states and observing the state changes. Based on the gathered information, it is possible to reverse-engineer the executed instructions. The processor acts as a kind of "instruction oracle."

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18533

    Last Modified: 21 Nov 2024

    The rimons-twitter-widget plugin before 1.3 for WordPress has XSS.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18532

    Last Modified: 21 Nov 2024

    The realty plugin before 1.1.0 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18531

    Last Modified: 21 Nov 2024

    The raygun4wp plugin before 1.8.3 for WordPress has XSS in the settings, a different issue than CVE-2017-9288.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18530

    Last Modified: 21 Nov 2024

    The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18529

    Last Modified: 21 Nov 2024

    The promobar plugin before 1.1.1 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18528

    Last Modified: 21 Nov 2024

    The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2015-9320

    Last Modified: 21 Nov 2024

    The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18527

    Last Modified: 21 Nov 2024

    The pagination plugin before 1.0.7 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2016-10895

    Last Modified: 21 Nov 2024

    The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18526

    Last Modified: 21 Nov 2024

    The moreads-se plugin before 1.4.7 for WordPress has XSS.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2015-9319

    Last Modified: 21 Nov 2024

    The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18524

    Last Modified: 16 Jul 2025

    The football-pool plugin before 2.6.5 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18519

    Last Modified: 21 Nov 2024

    The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2017-18523

    Last Modified: 21 Nov 2024

    The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18522

    Last Modified: 21 Nov 2024

    The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2016-10892

    Last Modified: 21 Nov 2024

    The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18566

    Last Modified: 21 Nov 2024

    The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18518

    Last Modified: 21 Nov 2024

    The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2018-20978

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.4.7 for WordPress has XSS.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18567

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.4.6 for WordPress has XSS.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2015-9329

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.2.5 for WordPress has reflected XSS.

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2015-9330

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2015-9331

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2016-10913

    Last Modified: 21 Nov 2024

    The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2016-10914

    Last Modified: 21 Nov 2024

    The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-15238

    Last Modified: 21 Nov 2024

    The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18568

    Last Modified: 21 Nov 2024

    The my-wp-translate plugin before 1.0.4 for WordPress has XSS.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2017-18569

    Last Modified: 21 Nov 2024

    The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2016-10915

    Last Modified: 21 Nov 2024

    The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18520

    Last Modified: 21 Nov 2024

    The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.

    Published: 20 Aug 2019
    6.5
    Medium

    CVE-2015-9332

    Last Modified: 21 Nov 2024

    The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2011-5328

    Last Modified: 21 Nov 2024

    The user-access-manager plugin before 1.2 for WordPress has CSRF.

    Published: 20 Aug 2019
    8.8
    High

    CVE-2014-10381

    Last Modified: 21 Nov 2024

    The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2015-9318

    Last Modified: 21 Nov 2024

    The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2017-18517

    Last Modified: 21 Nov 2024

    The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.

    Published: 20 Aug 2019
    6.1
    Medium

    CVE-2015-9317

    Last Modified: 21 Nov 2024

    The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.

    Published: 20 Aug 2019
    7.8
    High

    CVE-2019-14687

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

    Published: 20 Aug 2019