diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml
index a49e0d75..c4aa3510 100644
--- a/data/plugin_vulns.xml
+++ b/data/plugin_vulns.xml
@@ -2926,11 +2926,38 @@
- Buddypress <= 1.5.5 - SQL Injection
+ Buddypress <= 1.9.1 - Privilege Escalation
+ http://packetstormsecurity.com/files/125213/
+
+ UNKNOWN
+ 1.9.2
+
+
+ Buddypress <= 1.9.1 - Cross Site Scripting
+
+ http://packetstormsecurity.com/files/125212/
+
+ XSS
+ 1.9.2
+
+
+ Buddypress - player.swf / jwplayer.swf playerready Parameter XSS
+
+ 88886
+ http://packetstormsecurity.com/files/119020/
+ http://xforce.iss.net/xforce/xfdb/80840
+
+ XSS
+
+
+ Buddypress <= 1.5.4 - wp-load.php exclude Parameter SQL Injection
+
+ 80763
18690
SQLI
+ 1.5.5
@@ -7713,7 +7740,6 @@
Advanced XML Reader 0.1.1 - XML External Entity (XXE) Data Parsing Arbitrary File Disclosure
92904
- http://packetstormsecurity.com/files/121492/
http://seclists.org/bugtraq/2013/May/5
XXE
@@ -9923,6 +9949,15 @@
+
+ DZS Video Gallery - ajax.php source Parameter Reflected XSS
+
+ 103283
+ 56904
+ http://packetstormsecurity.com/files/125179/
+
+ RCE
+
DZS Video Gallery - upload.php File Upload Remote Code Execution