CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-26137

    Last Modified: 21 Nov 2024

    urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

    Published: 10 Feb 2020
    8.1
    High

    CVE-2020-5529

    Last Modified: 21 Nov 2024

    HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.

    Published: 10 Feb 2020
    4.3
    Medium

    CVE-2012-5570

    Last Modified: 21 Nov 2024

    The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.

    Published: 8 Feb 2020
    8.1
    High

    CVE-2012-4381

    Last Modified: 21 Nov 2024

    MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

    Published: 8 Feb 2020
    6.1
    Medium

    CVE-2012-4029

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.

    Published: 8 Feb 2020
    5.4
    Medium

    CVE-2015-2207

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (5) parent, (6) circuit, (7) return, (8) xname, or (9) mpTransactionId parameter.

    Published: 8 Feb 2020
    8.8
    High

    CVE-2015-3423

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9) filter_INSERT_COUNT, (10) filter_MINOR_FALLOUT, (11) filter_UPDATE_COUNT, (12) sort, or (13) sessid parameter.

    Published: 8 Feb 2020
    9.8
    Critical

    CVE-2014-8739

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension, then accessing it via a direct request to the file in files/, as exploited in the wild in October 2014.

    Published: 8 Feb 2020
    7.2
    High

    CVE-2015-2062

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to wp-admin/admin.php.

    Published: 8 Feb 2020
    7.5
    High

    CVE-2014-7863

    Last Modified: 21 Nov 2024

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.

    Published: 8 Feb 2020
    5.4
    Medium

    CVE-2015-1394

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.

    Published: 8 Feb 2020
    6.5
    Medium

    CVE-2014-9127

    Last Modified: 21 Nov 2024

    Open-School Community Edition 2.2 does not properly restrict access to the export functionality, which allows remote authenticated users to obtain sensitive information via the r parameter with the value export to index.php.

    Published: 8 Feb 2020
    6.1
    Medium

    CVE-2014-9126

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Open-School Community Edition 2.2 allow remote attackers to inject arbitrary web script or HTML via the YII_CSRF_TOKEN HTTP cookie or the StudentDocument, StudentCategories, StudentPreviousDatas parameters to index.php.

    Published: 8 Feb 2020
    6.1
    Medium

    CVE-2014-9470

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS before 3.8.4 allows remote attackers to inject arbitrary web script or HTML via the q_widget parameter to en/search.

    Published: 8 Feb 2020
    8.8
    High

    CVE-2014-2225

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified impact via a request to api/add/wlanconf; change the guest (3) password, (4) authentication method, or (5) restricted subnets via a request to api/set/setting/guest_access; (6) block, (7) unblock, or (8) reconnect users by MAC address via a request to api/cmd/stamgr; change the syslog (9) server or (10) port via a request to api/set/setting/rsyslogd; (11) have unspecified impact via a request to api/set/setting/smtp; change the syslog (12) server, (13) port, or (14) authentication settings via a request to api/cmd/cfgmgr; or (15) change the Unifi Controller name via a request to api/set/setting/identity.

    Published: 8 Feb 2020
    9.6
    Critical

    CVE-2011-3642

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.

    Published: 8 Feb 2020
    3.3
    Low

    CVE-2019-11485

    Last Modified: 21 Nov 2024

    Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.

    Published: 8 Feb 2020
    6.3
    Medium

    CVE-2019-11484

    Last Modified: 21 Nov 2024

    Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.

    Published: 8 Feb 2020
    7
    High

    CVE-2019-11483

    Last Modified: 3 Nov 2025

    Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

    Published: 8 Feb 2020
    4.2
    Medium

    CVE-2019-11482

    Last Modified: 21 Nov 2024

    Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.

    Published: 8 Feb 2020
    3.8
    Low

    CVE-2019-11481

    Last Modified: 21 Nov 2024

    Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.

    Published: 8 Feb 2020
    5.3
    Medium

    CVE-2019-20807

    Last Modified: 21 Nov 2024

    In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11758

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11760

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11762

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11763

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11765

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11759

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11761

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.

    Published: 8 Feb 2020
    5.5
    Medium

    CVE-2020-11764

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

    Published: 8 Feb 2020
    6.1
    Medium

    CVE-2020-8823

    Last Modified: 21 Nov 2024

    htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.

    Published: 8 Feb 2020
    7.8
    High

    CVE-2019-17136

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of DXF files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8776.

    Published: 7 Feb 2020
    7.8
    High

    CVE-2019-17135

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8775.

    Published: 7 Feb 2020
    7.8
    High

    CVE-2019-13334

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of DXF files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8774.

    Published: 7 Feb 2020
    7.8
    High

    CVE-2019-13333

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of DXF files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8773.

    Published: 7 Feb 2020
    4.3
    Medium

    CVE-2020-8811

    Last Modified: 21 Nov 2024

    ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2020-8812

    Last Modified: 21 Nov 2024

    Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.

    Published: 7 Feb 2020
    7.5
    High

    CVE-2019-19356

    Last Modified: 7 Nov 2025

    Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

    Published: 7 Feb 2020
    5.9
    Medium

    CVE-2019-13163

    Last Modified: 21 Nov 2024

    The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.

    Published: 7 Feb 2020
    7.8
    High

    CVE-2020-8808

    Last Modified: 21 Nov 2024

    The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, via a function call such as MmMapIoSpace.

    Published: 7 Feb 2020
    6.1
    Medium

    CVE-2011-1086

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter.

    Published: 7 Feb 2020
    8.8
    High

    CVE-2011-1085

    Last Modified: 21 Nov 2024

    CSRF vulnerability in Smoothwall Express 3.

    Published: 7 Feb 2020
    6.1
    Medium

    CVE-2011-1084

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.

    Published: 7 Feb 2020
    10
    Critical

    CVE-2020-6770

    Last Modified: 21 Nov 2024

    Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.

    Published: 7 Feb 2020
    8.6
    High

    CVE-2020-6768

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2020-8796

    Last Modified: 21 Nov 2024

    Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

    Published: 7 Feb 2020
    10
    Critical

    CVE-2020-6769

    Last Modified: 21 Nov 2024

    Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all cameras configured to be controlled by the VSG as well as the recording storage associated with the VSG. This affects Bosch Video Streaming Gateway versions 6.45 <= 6.45.08, 6.44 <= 6.44.022, 6.43 <= 6.43.0023 and 6.42.10 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable VSG version is installed with BVMS. This affects Bosch DIVAR IP 2000 <= 3.62.0019 and DIVAR IP 5000 <= 3.80.0039 if the corresponding port 8023 has been opened in the device's firewall.

    Published: 7 Feb 2020
    5.9
    Medium

    CVE-2013-3096

    Last Modified: 21 Nov 2024

    D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2013-3067

    Last Modified: 21 Nov 2024

    Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2013-3091

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

    Published: 7 Feb 2020