CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-9304

    Last Modified: 21 Nov 2024

    The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2018-20966

    Last Modified: 21 Nov 2024

    The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

    Published: 12 Aug 2019
    7.5
    High

    CVE-2019-14951

    Last Modified: 21 Nov 2024

    The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanism against brute-force attacks on the authentication process, which makes it easier for attackers to obtain multimedia-screen access via port 7050 on the cellular network, as demonstrated by a DrivingRestriction method call to uma/jsonrpc/mobile.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2017-18506

    Last Modified: 21 Nov 2024

    The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

    Published: 12 Aug 2019
    5.4
    Medium

    CVE-2019-14948

    Last Modified: 21 Nov 2024

    The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2019-14949

    Last Modified: 21 Nov 2024

    The wp-database-backup plugin before 5.1.2 for WordPress has XSS.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2016-10873

    Last Modified: 21 Nov 2024

    The wp-database-backup plugin before 4.3.3 for WordPress has XSS.

    Published: 12 Aug 2019
    8.8
    High

    CVE-2016-10874

    Last Modified: 21 Nov 2024

    The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2016-10875

    Last Modified: 21 Nov 2024

    The wp-database-backup plugin before 4.3.1 for WordPress has XSS.

    Published: 12 Aug 2019
    8.8
    High

    CVE-2016-10876

    Last Modified: 21 Nov 2024

    The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2016-10877

    Last Modified: 21 Nov 2024

    The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2016-10878

    Last Modified: 7 May 2025

    The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2015-9305

    Last Modified: 7 May 2025

    The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2019-14950

    Last Modified: 21 Nov 2024

    The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2017-18508

    Last Modified: 21 Nov 2024

    The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2016-10879

    Last Modified: 21 Nov 2024

    The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.

    Published: 12 Aug 2019
    6.1
    Medium

    CVE-2015-9306

    Last Modified: 21 Nov 2024

    The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.

    Published: 12 Aug 2019
    7.8
    High

    CVE-2019-10216

    Last Modified: 21 Nov 2024

    In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.

    Published: 12 Aug 2019
    7.5
    High

    CVE-2019-14932

    Last Modified: 21 Nov 2024

    The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resumeDetail.cfm. This includes personal information and other sensitive data.

    Published: 12 Aug 2019
    5.5
    Medium

    CVE-2019-14939

    Last Modified: 21 Nov 2024

    An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open by default.

    Published: 12 Aug 2019
    5.8
    Medium

    CVE-2019-15034

    Last Modified: 21 Nov 2024

    hw/display/bochs-display.c in QEMU 4.0.0 does not ensure a sufficient PCI config space allocation, leading to a buffer overflow involving the PCIe extended config space.

    Published: 12 Aug 2019
    4.2
    Medium

    CVE-2019-19537

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB character device driver layer, aka CID-303911cfc5b9. This affects drivers/usb/core/file.c.

    Published: 12 Aug 2019
    7.8
    High

    CVE-2019-14935

    Last Modified: 21 Nov 2024

    3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control access for Everyone, and leading to privilege escalation because of a StartUp link.

    Published: 11 Aug 2019
    7.8
    High

    CVE-2019-14934

    Last Modified: 21 Nov 2024

    An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.

    Published: 11 Aug 2019
    8.8
    High

    CVE-2019-14933

    Last Modified: 21 Nov 2024

    Bagisto 0.1.5 allows CSRF under /admin URIs.

    Published: 11 Aug 2019
    7.5
    High

    CVE-2019-14924

    Last Modified: 21 Nov 2024

    An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessible file be available (the credential of the app, for instance).

    Published: 10 Aug 2019
    2.4
    Low

    CVE-2019-14357

    Last Modified: 21 Nov 2024

    On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that an attack is not "realistically implementable.

    Published: 10 Aug 2019
    2.4
    Low

    CVE-2019-14355

    Last Modified: 21 Nov 2024

    On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover secret data shown on the display. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is "insignificant risk.

    Published: 10 Aug 2019
    2.4
    Low

    CVE-2019-14354

    Last Modified: 21 Nov 2024

    On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data.

    Published: 10 Aug 2019
    8.1
    High

    CVE-2019-9506

    Last Modified: 21 Nov 2024

    The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

    Published: 10 Aug 2019
    9.1
    Critical

    CVE-2019-17362

    Last Modified: 21 Nov 2024

    In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.

    Published: 10 Aug 2019
    7.5
    High

    CVE-2017-18594

    Last Modified: 21 Nov 2024

    nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.

    Published: 10 Aug 2019
    6.1
    Medium

    CVE-2019-14807

    Last Modified: 21 Nov 2024

    In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/specials/MobileSpecialPageFeed.php.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-12261

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-12260

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

    Published: 9 Aug 2019
    7.5
    High

    CVE-2019-12258

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.

    Published: 9 Aug 2019
    4.3
    Medium

    CVE-2018-20826

    Last Modified: 21 Nov 2024

    The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.

    Published: 9 Aug 2019
    5.4
    Medium

    CVE-2018-20827

    Last Modified: 21 Nov 2024

    The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-11581

    Last Modified: 24 Oct 2025

    There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

    Published: 9 Aug 2019
    6.1
    Medium

    CVE-2019-11274

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-12255

    Last Modified: 21 Nov 2024

    Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

    Published: 9 Aug 2019
    7.8
    High

    CVE-2019-3744

    Last Modified: 21 Nov 2024

    Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.

    Published: 9 Aug 2019
    7.8
    High

    CVE-2019-3742

    Last Modified: 21 Nov 2024

    Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a named pipe that performs binary deserialization via a process hollowing technique to inject malicous code to run an executable with elevated privileges.

    Published: 9 Aug 2019
    5.3
    Medium

    CVE-2019-12265

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.

    Published: 9 Aug 2019
    8.1
    High

    CVE-2019-12263

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

    Published: 9 Aug 2019
    7.5
    High

    CVE-2019-12259

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

    Published: 9 Aug 2019
    6.5
    Medium

    CVE-2019-5498

    Last Modified: 21 Nov 2024

    OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.

    Published: 9 Aug 2019
    9.8
    Critical

    CVE-2019-12256

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.

    Published: 9 Aug 2019
    8.8
    High

    CVE-2019-12257

    Last Modified: 21 Nov 2024

    Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

    Published: 9 Aug 2019
    6.5
    Medium

    CVE-2019-5408

    Last Modified: 21 Nov 2024

    Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are affected. DevMgr version 7.0.0-00 to earlier than 8.6.1-02 RepMgr if it is installed on the same machine as DevMgr TSMgr if it is installed on the same machine as DevMgr. The resolution is to upgrade to the fixed version as described below or later version of DevMgr 8.6.2-02 or later. RepMgr and TSMgr will be corrected by upgrading DevMgr.

    Published: 9 Aug 2019