CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc.
WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Pan-os, Pa-7050, Pa-7080, Bridgecrew_checkov, Content_update330, Cortex_xdr_agent, Cortex_xsoar, Demisto, Expedition, Expedition_migration_tool
2020-02-10
N/A
6.1 MEDIUM
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_email= XSS.
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
