CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-4427

    Last Modified: 21 Nov 2024

    IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.

    Published: 12 Feb 2020
    6.1
    Medium

    CVE-2013-2637

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

    Published: 12 Feb 2020
    5.9
    Medium

    CVE-2013-6681

    Last Modified: 21 Nov 2024

    Tube Map Live Underground for Android before 3.0.22 has an Information Disclosure Vulnerability

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2013-6236

    Last Modified: 21 Nov 2024

    IZON IP 2.0.2: hard-coded password vulnerability

    Published: 12 Feb 2020
    7
    High

    CVE-2013-3685

    Last Modified: 21 Nov 2024

    A Privilege Escalation Vulnerability exists in Sprite Software Spritebud 1.3.24 and 1.3.28 and Backup 2.5.4105 and 2.5.4108 on LG Android smartphones due to a race condition in the spritebud daemon, which could let a local malicious user obtain root privileges.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2013-1924

    Last Modified: 21 Nov 2024

    Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2

    Published: 12 Feb 2020
    6.1
    Medium

    CVE-2013-4395

    Last Modified: 21 Nov 2024

    Simple Machines Forum (SMF) through 2.0.5 has XSS

    Published: 12 Feb 2020
    7.8
    High

    CVE-2013-3494

    Last Modified: 21 Nov 2024

    A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2013-4090

    Last Modified: 21 Nov 2024

    Varnish HTTP cache before 3.0.4: ACL bug

    Published: 12 Feb 2020
    7.8
    High

    CVE-2013-2097

    Last Modified: 21 Nov 2024

    ZPanel through 10.1.0 has Remote Command Execution

    Published: 12 Feb 2020
    6.1
    Medium

    CVE-2013-1938

    Last Modified: 21 Nov 2024

    Zimbra 2013 has XSS in aspell.php

    Published: 12 Feb 2020
    6.1
    Medium

    CVE-2013-1410

    Last Modified: 21 Nov 2024

    Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities

    Published: 12 Feb 2020
    5.5
    Medium

    CVE-2015-7890

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2013-2010

    Last Modified: 21 Nov 2024

    WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

    Published: 12 Feb 2020
    6.1
    Medium

    CVE-2020-8839

    Last Modified: 21 Nov 2024

    Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2020-8815

    Last Modified: 21 Nov 2024

    Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2020-2133

    Last Modified: 21 Nov 2024

    Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2020-2130

    Last Modified: 21 Nov 2024

    Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2020-2131

    Last Modified: 21 Nov 2024

    Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2020-2132

    Last Modified: 21 Nov 2024

    Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2128

    Last Modified: 21 Nov 2024

    Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2020-2129

    Last Modified: 21 Nov 2024

    Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2126

    Last Modified: 21 Nov 2024

    Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2127

    Last Modified: 21 Nov 2024

    Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2125

    Last Modified: 21 Nov 2024

    Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2123

    Last Modified: 21 Nov 2024

    Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2124

    Last Modified: 21 Nov 2024

    Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2121

    Last Modified: 21 Nov 2024

    Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

    Published: 12 Feb 2020
    5.4
    Medium

    CVE-2020-2122

    Last Modified: 21 Nov 2024

    Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.

    Published: 12 Feb 2020
    5.3
    Medium

    CVE-2020-2119

    Last Modified: 21 Nov 2024

    Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2120

    Last Modified: 21 Nov 2024

    Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2118

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2116

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2020-2117

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2020-2114

    Last Modified: 21 Nov 2024

    Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2115

    Last Modified: 21 Nov 2024

    Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

    Published: 12 Feb 2020
    5.4
    Medium

    CVE-2020-2113

    Last Modified: 21 Nov 2024

    Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.

    Published: 12 Feb 2020
    5.4
    Medium

    CVE-2020-2112

    Last Modified: 21 Nov 2024

    Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2020-2110

    Last Modified: 21 Nov 2024

    Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2015-5617

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2013-7381

    Last Modified: 21 Nov 2024

    libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2019-19194

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices installs a zero long term key (LTK) if an out-of-order link-layer encryption request is received during Secure Connections pairing. An attacker in radio range can have arbitrary read/write access to protected GATT service data, cause a device crash, or possibly control a device's function by establishing an encrypted session with the zero LTK.

    Published: 12 Feb 2020
    6.5
    Medium

    CVE-2019-19196

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before November 2019 for TLSR8x5x through 3.4.0, TLSR823x through 1.3.0, and TLSR826x through 3.3 devices accepts a pairing request with a key size greater than 16 bytes, allowing an attacker in radio range to cause a buffer overflow and denial of service (crash) via crafted packets.

    Published: 12 Feb 2020
    4.7
    Medium

    CVE-2019-20100

    Last Modified: 21 Nov 2024

    The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2019-20099

    Last Modified: 21 Nov 2024

    The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

    Published: 12 Feb 2020
    4.3
    Medium

    CVE-2019-20098

    Last Modified: 21 Nov 2024

    The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.

    Published: 12 Feb 2020
    9.8
    Critical

    CVE-2013-7378

    Last Modified: 21 Nov 2024

    scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2009-5139

    Last Modified: 21 Nov 2024

    The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

    Published: 12 Feb 2020
    8.8
    High

    CVE-2009-5140

    Last Modified: 21 Nov 2024

    The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

    Published: 12 Feb 2020
    7.5
    High

    CVE-2014-2560

    Last Modified: 21 Nov 2024

    The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

    Published: 12 Feb 2020