| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-21003 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The buddyforms plugin before 2.2.8 for WordPress has SQL injection. | ||
| CVE-2016-10935 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation. | ||
| CVE-2015-9344 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The link-log plugin before 2.1 for WordPress has SQL injection. | ||
| CVE-2019-15657 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2019 | In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. | ||
| CVE-2019-15651 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex. | ||
| CVE-2019-15497 | Cri | 0.64 | 9.8 | 0.03 | Aug 26, 2019 | Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. | ||
| CVE-2019-9569 | Cri | 0.64 | 9.8 | 0.05 | Aug 26, 2019 | Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors. | ||
| CVE-2019-8001 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7998 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7997 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7993 | Cri | 0.64 | 9.8 | 0.08 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7992 | Cri | 0.64 | 9.8 | 0.05 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7990 | Cri | 0.64 | 9.8 | 0.08 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7975 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7974 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7973 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7972 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7971 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7970 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7969 | Cri | 0.64 | 9.8 | 0.06 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-7968 | Cri | 0.64 | 9.8 | 0.07 | Aug 26, 2019 | Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | ||
| CVE-2019-15548 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled. | ||
| CVE-2019-15543 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases. | ||
| CVE-2019-15533 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. | ||
| CVE-2019-15503 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter. | ||
| CVE-2019-13020 | Cri | 0.65 | 10.0 | 0.01 | Aug 26, 2019 | The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve… | ||
| CVE-2018-20998 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption. | ||
| CVE-2018-20997 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing. | ||
| CVE-2018-20996 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. | ||
| CVE-2018-20995 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled. | ||
| CVE-2019-15558 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. | ||
| CVE-2019-15557 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. | ||
| CVE-2019-15555 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php. | ||
| CVE-2019-15560 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. | ||
| CVE-2019-15559 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | DianoxDragon Hawn before 2019-07-10 allows SQL injection. | ||
| CVE-2019-4169 | Cri | 0.59 | 9.1 | 0.02 | Aug 26, 2019 | IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702. | ||
| CVE-2019-15574 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. | ||
| CVE-2019-15573 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. | ||
| CVE-2019-15572 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. | ||
| CVE-2019-15571 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. | ||
| CVE-2019-15570 | Cri | 0.57 | 9.8 | 0.01 | Aug 26, 2019 | BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. | ||
| CVE-2019-15569 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java. | ||
| CVE-2019-15568 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. | ||
| CVE-2019-15567 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. | ||
| CVE-2019-15566 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. | ||
| CVE-2019-15565 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. | ||
| CVE-2019-15564 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2019 | The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. | ||
| CVE-2019-15563 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2019 | Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java. | ||
| CVE-2019-15554 | Cri | 0.64 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity. | ||
| CVE-2019-15552 | Cri | 0.57 | 9.8 | 0.02 | Aug 26, 2019 | An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution. |
- risk 0.64cvss 9.8epss 0.02
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
- risk 0.64cvss 9.8epss 0.02
The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
- risk 0.64cvss 9.8epss 0.02
The link-log plugin before 2.1 for WordPress has SQL injection.
- risk 0.57cvss 9.8epss 0.02
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.
- risk 0.64cvss 9.8epss 0.03
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
- risk 0.64cvss 9.8epss 0.05
Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.08
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.05
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.08
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.06
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.07
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.
- risk 0.64cvss 9.8epss 0.01
XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
- risk 0.64cvss 9.8epss 0.02
cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.
- risk 0.65cvss 10.0epss 0.01
The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve…
- risk 0.57cvss 9.8epss 0.02
An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.
- risk 0.64cvss 9.8epss 0.01
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
- risk 0.64cvss 9.8epss 0.02
XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
- risk 0.64cvss 9.8epss 0.01
FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.
- risk 0.64cvss 9.8epss 0.01
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
- risk 0.64cvss 9.8epss 0.01
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
- risk 0.59cvss 9.1epss 0.02
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
- risk 0.64cvss 9.8epss 0.01
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
- risk 0.64cvss 9.8epss 0.01
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
- risk 0.57cvss 9.8epss 0.01
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
- risk 0.64cvss 9.8epss 0.01
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.
- risk 0.64cvss 9.8epss 0.01
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
- risk 0.64cvss 9.8epss 0.01
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
- risk 0.64cvss 9.8epss 0.02
The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
- risk 0.64cvss 9.8epss 0.01
The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
- risk 0.64cvss 9.8epss 0.01
The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
- risk 0.57cvss 9.8epss 0.02
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.
- risk 0.57cvss 9.8epss 0.02
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.