|
266431
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attac…
|
CWE-20
Improper Input Validation
|
CVE-2015-9544
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266432
|
7.5 |
HIGH
Network
|
freeradius debian canonical
|
pam_radius debian_linux ubuntu_linux
|
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-9542
|
2024-11-21 11:40 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266433
|
3.3 |
LOW
Local
|
openstack
|
nova
|
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
|
CWE-200
Information Exposure
|
CVE-2015-9543
|
2024-11-21 11:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266434
|
7.5 |
HIGH
Network
|
qt fedoraproject
|
qt fedora
|
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
|
CWE-776
XML Entity Expansion
|
CVE-2015-9541
|
2024-11-21 11:40 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266435
|
6.1 |
MEDIUM
Network
|
chamilo
|
chamilo_lms
|
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
|
CWE-601
Open Redirect
|
CVE-2015-9540
|
2024-11-21 11:40 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266436
|
6.1 |
MEDIUM
Network
|
fast_secure_contact_form_project
|
fast_secure_contact_form
|
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9539
|
2024-11-21 11:40 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266437
|
6.5 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
|
CWE-22
Path Traversal
|
CVE-2015-9538
|
2024-11-21 11:40 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266438
|
5.4 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9537
|
2024-11-21 11:40 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266439
|
6.1 |
MEDIUM
Network
|
sandhillsdev easydigitaldownloads
|
easy_digital_downloads recount_earnings
|
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9524
|
2024-11-21 11:40 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266440
|
6.1 |
MEDIUM
Network
|
sandhillsdev easydigitaldownloads
|
easy_digital_downloads recommended_products
|
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9523
|
2024-11-21 11:40 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|