Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

7,142 of 17,305 · Page 27/143
8.8
CVE-2016-10885

The wp-editor plugin before 1.2.6 for WordPress has CSRF.

8.8
CVE-2017-18510

The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio

8.8
CVE-2017-18511

The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

8.8
CVE-2017-18512

The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.

8.8
CVE-2017-18513

The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.

8.8
CVE-2018-20967

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

8.8
CVE-2018-20968

The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

8.8
CVE-2019-15047

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBit

8.8
CVE-2019-15048

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4Rtp

8.8
CVE-2019-15049

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4D

8.8
CVE-2019-15050

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4A

8.8
CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a

8.8
CVE-2019-12104

The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-au

8.8
CVE-2019-14216

An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/ad

8.8
CVE-2019-1140

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi

8.8
CVE-2019-1144

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1145

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1149

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1150

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1151

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1152

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2019-1183

This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates f

8.8
CVE-2019-1229

An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vul

8.8
CVE-2019-1258

An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in th

8.8
CVE-2019-14755

The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type

8.8
CVE-2019-3417

All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insuffi

8.8
CVE-2019-14788

wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPres

8.8
CVE-2019-14422

An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w

8.8
CVE-2019-9013

An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which res

8.8
CVE-2018-14668

In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat

8.8
CVE-2019-12809

Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attacke

8.8
CVE-2019-13516

In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forge

8.8
CVE-2019-12791

A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to

8.8
CVE-2019-12792

A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escala

8.8
CVE-2019-15104

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT

8.8
CVE-2019-15105

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in

8.8
CVE-2019-14923

EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.

8.8
CVE-2015-9322

The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.

8.8
CVE-2017-18544

The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.

8.8
CVE-2017-18546

The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.

8.8
CVE-2017-18547

The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

8.8
CVE-2018-20971

The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.

8.8
CVE-2018-20972

The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.

8.8
CVE-2018-20974

The js-jobs plugin before 1.0.7 for WordPress has CSRF.

8.8
CVE-2019-15113

The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.

8.8
CVE-2019-15114

The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.

8.8
CVE-2019-15115

The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.

8.8
CVE-2019-15140

coders/mat.c in ImageMagick 7.0.8-43 Q16 allows remote attackers to cause a denial of service (use-after-free and applic

8.8
CVE-2019-15150

In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n

8.8
CVE-2019-15229

FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started