• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-15335
Lavamobiles, Z92 Firmware
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
CVE-2019-15334
Iris 88 Firmware, Lavamobiles
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
CVE-2019-15333
Flair Z1 Firmware, Lavamobiles
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2019-11-22
N/A
3.3 LOW
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
CVE-2019-15332
Lavamobiles, Z61 Firmware
Z61_firmware, Z61, Flair_z1_firmware, Flair_z1, Iris_88_firmware, Iris_88, Z92_firmware, Z92, Z81_firmware, Z81
2020-08-24
N/A
3.3 LOW
The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
CVE-2019-15331
2020-08-24
N/A
6.1 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
CVE-2019-15330
2021-07-21
N/A
7.5 HIGH
The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading.
CVE-2019-1533
2020-01-24
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-15329
2019-08-23
N/A
8.8 HIGH
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
CVE-2019-15328
2019-08-23
N/A
6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CVE-2019-15327
2019-08-23
N/A
6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
« Previous 1 … 6,127 6,128 6,129 6,130 6,131 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE