CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection.
The buddyforms plugin before 2.2.8 for WordPress has SQL injection.
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
The anycomment plugin before 0.0.33 for WordPress has XSS.
An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong order, causing heap memory corruption.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.
