• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-9576
2021-02-24
N/A
6.1 MEDIUM
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
CVE-2019-9575
2019-03-06
N/A
6.1 MEDIUM
The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS.
CVE-2019-9574
2020-08-24
N/A
7.5 HIGH
The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.
CVE-2019-9573
2019-03-21
N/A
7.5 HIGH
The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications.
CVE-2019-9572
2019-03-08
N/A
7.2 HIGH
SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type to application/zip, and placing PHP code after the ZIP header. This ultimately allows execution of arbitrary PHP code in PublicHome1_Static.php because of mishandling in the ApplicationAdminControllerThemeController.class.php Upload() function.
CVE-2019-9570
2019-03-05
N/A
4.8 MEDIUM
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
CVE-2019-9569
Deltacontrols, Entelibus Firmware
Entelibus_firmware, Entelibus
2021-07-21
N/A
9.8 CRITICAL
Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors.
CVE-2019-9568
2019-03-07
N/A
6.5 MEDIUM
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
CVE-2019-9567
2019-03-07
N/A
6.1 MEDIUM
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
CVE-2019-9566
2019-03-05
N/A
9.8 CRITICAL
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
« Previous 1 … 5,078 5,079 5,080 5,081 5,082 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE