Latest CVE Feed
-
6.1
MEDIUMCVE-2015-9306
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.... Read more
Affected Products : import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv- Published: Aug. 12, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9304
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.... Read more
Affected Products : ultimate_member- Published: Aug. 12, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9303
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.... Read more
Affected Products : simple_share_buttons_adder- Published: Aug. 12, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9302
The simple-fields plugin before 1.4.11 for WordPress has XSS.... Read more
Affected Products : simple_fields- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9301
The liveforms plugin before 3.2.0 for WordPress has SQL injection.... Read more
Affected Products : live_forms- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9300
The events-manager plugin before 5.5.7 for WordPress has multiple XSS issues.... Read more
- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9296
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.... Read more
Affected Products : download_monitor- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9295
The contact-form-plugin plugin before 3.96 for WordPress has XSS.... Read more
Affected Products : contact_form- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9294
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.... Read more
Affected Products : all_in_one_wp_security_\&_firewall- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9293
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.... Read more
Affected Products : all_in_one_wp_security_\&_firewall- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-9292
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).... Read more
Affected Products : 6kbbs- Published: Aug. 08, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-9291
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9290
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.... Read more
Affected Products : freetype- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-9289
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as ... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-9288
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials... Read more
Affected Products : web_player- Published: Jul. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9287
Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not signed like the... Read more
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-9286
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.... Read more
Affected Products : nodebb- Published: Apr. 30, 2019
- Modified: Nov. 21, 2024