|
211321
|
6.1 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9304
|
2024-11-21 11:40 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211322
|
6.1 |
MEDIUM
Network
|
simplesharebuttons
|
simple_share_buttons_adder
|
The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9303
|
2024-11-21 11:40 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211323
|
6.1 |
MEDIUM
Network
|
smackcoders
|
import_all_pages\ _post_types\ _products\ _orders\ _and_users_as_xml_\&_csv
|
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9306
|
2024-11-21 11:40 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211324
|
6.1 |
MEDIUM
Network
|
flippercode
|
wp_google_map
|
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9305
|
2024-11-21 11:40 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211325
|
8.8 |
HIGH
Network
|
6kbbs
|
6kbbs
|
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
|
CWE-352
Origin Validation Error
|
CVE-2015-9292
|
2024-11-21 11:40 |
2019-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211326
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).
|
CWE-284
Improper Access Control
|
CVE-2015-9291
|
2024-11-21 11:40 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211327
|
9.8 |
CRITICAL
Network
|
freetype
|
freetype
|
In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again.
|
CWE-125
Out-of-bounds Read
|
CVE-2015-9290
|
2024-11-21 11:40 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211328
|
6.5 |
MEDIUM
Network
|
unity
|
web_player
|
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
|
CWE-200
Information Exposure
|
CVE-2015-9288
|
2024-11-21 11:40 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211329
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the usersp…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-9289
|
2024-11-21 11:40 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211330
|
9.8 |
CRITICAL
Network
|
cam
|
the_university_of_cambridge_web_authentication_system_apache_authentication_agent
|
Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulate…
|
CWE-22
Path Traversal
|
CVE-2015-9287
|
2024-11-21 11:40 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|