CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2014-5087

    Last Modified: 21 Nov 2024

    A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2014-5091

    Last Modified: 21 Nov 2024

    A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.

    Published: 7 Feb 2020
    5.3
    Medium

    CVE-2014-5278

    Last Modified: 21 Nov 2024

    A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.

    Published: 7 Feb 2020
    8.8
    High

    CVE-2014-5288

    Last Modified: 21 Nov 2024

    A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2018-5746

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-6466

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2017-3149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2017-3148

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2017-3146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2017-3147

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 7 Feb 2020
    8.8
    High

    CVE-2014-5468

    Last Modified: 21 Nov 2024

    A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

    Published: 7 Feb 2020
    6.1
    Medium

    CVE-2014-6413

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2020-1768

    Last Modified: 21 Nov 2024

    The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5664

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5663

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5661

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5662

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5659

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5660

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5656

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5657

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5658

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5653

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5654

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5655

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5652

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5651

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2019-5650

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Feb 2020
    8.8
    High

    CVE-2014-7224

    Last Modified: 21 Nov 2024

    A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.

    Published: 7 Feb 2020
    7
    High

    CVE-2019-18988

    Last Modified: 7 Nov 2025

    TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system.

    Published: 7 Feb 2020
    —
    Unknown

    CVE-2008-3793

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3792. Reason: This candidate is a duplicate of CVE-2008-3792. Notes: All CVE users should reference CVE-2008-3792 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Feb 2020
    5.3
    Medium

    CVE-2010-4658

    Last Modified: 21 Nov 2024

    statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2014-9530

    Last Modified: 21 Nov 2024

    A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.

    Published: 7 Feb 2020
    7.8
    High

    CVE-2020-8126

    Last Modified: 21 Nov 2024

    A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15).

    Published: 7 Feb 2020
    7.1
    High

    CVE-2019-16155

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched process. Further more, FortiClient for Linux 6.2.2 and below allow low privilege user write the system backup file under root privilege through GUI thus can cause root system file overwrite.

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2013-3637

    Last Modified: 21 Nov 2024

    ProjectPier 0.8.8 does not use the Secure flag for cookies

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2013-3636

    Last Modified: 21 Nov 2024

    ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag

    Published: 7 Feb 2020
    5.4
    Medium

    CVE-2013-3635

    Last Modified: 21 Nov 2024

    ProjectPier 0.8.8 has stored XSS

    Published: 7 Feb 2020
    8.8
    High

    CVE-2013-3629

    Last Modified: 21 Nov 2024

    ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

    Published: 7 Feb 2020
    8.8
    High

    CVE-2013-3628

    Last Modified: 21 Nov 2024

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

    Published: 7 Feb 2020
    8.8
    High

    CVE-2013-3591

    Last Modified: 21 Nov 2024

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2013-4335

    Last Modified: 21 Nov 2024

    opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2013-4334

    Last Modified: 21 Nov 2024

    opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

    Published: 7 Feb 2020
    9.8
    Critical

    CVE-2019-17268

    Last Modified: 21 Nov 2024

    The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

    Published: 7 Feb 2020
    7.5
    High

    CVE-2013-1202

    Last Modified: 21 Nov 2024

    Cisco ACE A2(3.6) allows log retention DoS.

    Published: 7 Feb 2020
    4.9
    Medium

    CVE-2013-0192

    Last Modified: 21 Nov 2024

    File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

    Published: 7 Feb 2020
    7.5
    High

    CVE-2012-1567

    Last Modified: 21 Nov 2024

    LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintUpdate.

    Published: 7 Feb 2020
    7.5
    High

    CVE-2012-1566

    Last Modified: 21 Nov 2024

    LinuxMint as of 2012-03-19 has temporary file creation vulnerabilities in mintNanny.

    Published: 7 Feb 2020
    8.8
    High

    CVE-2013-2009

    Last Modified: 21 Nov 2024

    WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution

    Published: 7 Feb 2020
    6.1
    Medium

    CVE-2020-8788

    Last Modified: 21 Nov 2024

    Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parameter. NOTE: the issues/227 reference does not imply that the affected product can be downloaded from GitHub. It was simply a convenient location for a public bug report.

    Published: 7 Feb 2020