• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-15123
2020-06-23
N/A
7.2 HIGH
The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker could use this to upload a malicious .aspx file and gain Remote Code Execution on the site.
CVE-2019-15120
2019-09-26
N/A
6.1 MEDIUM
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVE-2019-1512
2020-01-24
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-15119
2020-08-24
N/A
5.5 MEDIUM
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
CVE-2019-15118
2020-08-24
N/A
5.5 MEDIUM
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15117
2019-09-06
N/A
7.8 HIGH
parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15116
Easy Digital Downloads, Sandhillsdev
Easy_digital_downloads
2021-11-02
N/A
6.1 MEDIUM
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
CVE-2019-15115
2021-12-06
N/A
8.8 HIGH
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
CVE-2019-15114
2019-08-21
N/A
8.8 HIGH
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
CVE-2019-15113
2019-08-21
N/A
8.8 HIGH
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
« Previous 1 … 6,144 6,145 6,146 6,147 6,148 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE