CVE-2015-9355
The two-factor-authentication plugin before 1.1.0 for WordPress has XSS in the admin area.
Source: CVE-2015-9355
CVE-2015-9355
The two-factor-authentication plugin before 1.1.0 for WordPress has XSS in the admin area.
Source: CVE-2015-9355
CVE-2015-9360
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
Source: CVE-2015-9360
CVE-2011-5329
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
Source: CVE-2011-5329
CVE-2015-9353
The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-2015-4066.
Source: CVE-2015-9353
CVE-2012-6718
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
Source: CVE-2012-6718
CVE-2012-6717
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
Source: CVE-2012-6717
CVE-2012-6719
The sharebar plugin before 1.2.2 for WordPress has SQL injection.
Source: CVE-2012-6719
CVE-2019-15701
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim’s machine) when the search function’s autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing JavaScript in its name.
Source: CVE-2019-15701
CVE-2019-13269
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field.
Source: CVE-2019-13269
CVE-2019-15700
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and thus is affected by crafted "changed value of" text.
Source: CVE-2019-15700