Search Results (88023 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15837 1 Bitwise-it 1 Webp Express 2024-11-21 N/A
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15836 1 Bootstrapped 1 Wp Ultimate Recipe 2024-11-21 N/A
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CVE-2019-15833 1 Simple Mail Address Encoder Project 1 Simple Mail Address Encoder 2024-11-21 6.1 Medium
The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
CVE-2019-15830 1 Icegram 1 Icegram Engage 2024-11-21 N/A
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
CVE-2019-15829 1 Greentreelabs 1 Gallery Photoblocks 2024-11-21 N/A
The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS.
CVE-2019-15827 1 Onesignal 1 Onesignal-free-web-push-notifications 2024-11-21 N/A
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
CVE-2019-15817 1 Realestateconnected 1 Easy Property Listings 2024-11-21 N/A
The easy-property-listings plugin before 3.4 for WordPress has XSS.
CVE-2019-15816 1 Wpexpertdeveloper 1 Wp Private Content Plus 2024-11-21 N/A
The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions.
CVE-2019-15814 1 Sentrifugo 1 Sentrifugo 2024-11-21 N/A
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
CVE-2019-15811 1 Domainmod 1 Domainmod 2024-11-21 N/A
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
CVE-2019-15810 1 Netdisco 1 Netdisco 2024-11-21 6.1 Medium
Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL parameter.
CVE-2019-15802 1 Zyxel 18 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 15 more 2024-11-21 5.9 Medium
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt all passwords using AES256 in CBC mode. With the parameters known, all previously encrypted passwords can be decrypted. This includes the passwords that are part of configuration backups or otherwise embedded as part of the firmware.
CVE-2019-15801 1 Zyxel 18 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 15 more 2024-11-21 7.5 High
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to authenticate users wishing to access a diagnostics or password-recovery menu. Using the hardcoded cryptographic key found elsewhere in the firmware, these passwords can be decrypted. This is related to fds_sys_passDebugPasswd_ret() and fds_sys_passRecoveryPasswd_ret() in libfds.so.0.0.
CVE-2019-15800 1 Zyxel 18 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 15 more 2024-11-21 9.8 Critical
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could leverage these functions to call system() and execute arbitrary commands on the switches. (Note that these functions are currently not called in this version of the firmware, however an attacker could use other vulnerabilities to finally use these vulnerabilities to gain code execution.)
CVE-2019-15782 1 Webtorrent 1 Webtorrent 2024-11-21 N/A
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
CVE-2019-15778 1 Getwooplugins 1 Additional Variation Images For Woocommerce 2024-11-21 N/A
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
CVE-2019-15777 1 Shapepress 1 Wp Dsgvo Tools 2024-11-21 N/A
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
CVE-2019-15767 1 Gnu 1 Chess 2024-11-21 N/A
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
CVE-2019-15753 1 Openstack 1 Os-vif 2024-11-21 N/A
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network performance and allows users to possibly view the content of packets for instances belonging to other tenants sharing the same network. Only deployments using the linuxbridge backend are affected. This occurs in PyRoute2.add() in internal/command/ip/linux/impl_pyroute2.py.
CVE-2019-15750 1 Sitos 1 Sitos Six 2024-11-21 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.