Security
Headlines
HeadlinesLatestCVEs

Tag

#perl

CVE-2015-9298: Events Manager

The events-manager plugin before 5.6 for WordPress has code injection.

CVE
#sql#xss#csrf#vulnerability#web#ios#windows#apple#google#js#git#java#wordpress#php#perl#pdf#oauth#auth#firefox#sap#ssl
CVE-2019-13418: CVE - advisory - Search Guard

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

CVE-2019-14787: Newsletters

The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter.

CVE-2019-14683: Import and export users and customers

The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

CVE-2019-1949: Cisco Security Advisory: Cisco Firepower Management Center Persistent Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.