CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2011-1597

    Last Modified: 21 Nov 2024

    OpenVAS Manager v2.0.3 allows plugin remote code execution.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2011-1517

    Last Modified: 21 Nov 2024

    SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

    Published: 5 Feb 2020
    9.1
    Critical

    CVE-2011-1151

    Last Modified: 21 Nov 2024

    Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2011-1150

    Last Modified: 21 Nov 2024

    bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2020-8644

    Last Modified: 7 Nov 2025

    PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

    Published: 5 Feb 2020
    4.3
    Medium

    CVE-2013-2682

    Last Modified: 21 Nov 2024

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2013-2681

    Last Modified: 21 Nov 2024

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2013-2680

    Last Modified: 21 Nov 2024

    Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2011-1069

    Last Modified: 21 Nov 2024

    PHPShop through 0.8.1 has XSS.

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2011-1009

    Last Modified: 21 Nov 2024

    Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.

    Published: 5 Feb 2020
    5.4
    Medium

    CVE-2020-6854

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API.

    Published: 5 Feb 2020
    8.8
    High

    CVE-2011-0525

    Last Modified: 21 Nov 2024

    Batavi before 1.0 has CSRF.

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-8641

    Last Modified: 21 Nov 2024

    Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter.

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2019-20173

    Last Modified: 21 Nov 2024

    The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

    Published: 5 Feb 2020
    5.5
    Medium

    CVE-2011-0220

    Last Modified: 21 Nov 2024

    Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2019-20447

    Last Modified: 21 Nov 2024

    Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2010-4815

    Last Modified: 21 Nov 2024

    Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2015-5626

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2015-5628

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2015-5627

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet.

    Published: 5 Feb 2020
    —
    Unknown

    CVE-2013-5989

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4969. Reason: This candidate is a duplicate of CVE-2011-4969. Notes: All CVE users should reference CVE-2011-4969 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2020
    —
    Unknown

    CVE-2014-3893

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of CVE-2014-0114. Notes: All CVE users should reference CVE-2014-0114 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2010-4662

    Last Modified: 21 Nov 2024

    PmWiki before 2.2.21 has XSS.

    Published: 5 Feb 2020
    6.5
    Medium

    CVE-2020-3120

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 5 Feb 2020
    4.8
    Medium

    CVE-2020-3149

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing malicious data to a specific field within the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. Cisco ISE Software releases 2.7.0 and later contains the fix for this vulnerability.

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-3119

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-3118

    Last Modified: 28 Oct 2025

    A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-3111

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent).

    Published: 5 Feb 2020
    8.8
    High

    CVE-2020-3110

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to the targeted IP Camera. A successful exploit could allow the attacker to expose the affected IP Camera for remote code execution or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). This vulnerability is fixed in Video Surveillance 8000 Series IP Camera Firmware Release 1.0.7 and later.

    Published: 5 Feb 2020
    6.5
    Medium

    CVE-2013-2675

    Last Modified: 21 Nov 2024

    Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-3123

    Last Modified: 21 Nov 2024

    A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the optional DLP feature. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.

    Published: 5 Feb 2020
    4.8
    Medium

    CVE-2019-15253

    Last Modified: 23 Jul 2025

    A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker needs administrator credentials. This vulnerability affects Cisco DNA Center Software releases earlier than 1.3.0.6 and 1.3.1.4.

    Published: 5 Feb 2020
    8.1
    High

    CVE-2015-0102

    Last Modified: 21 Nov 2024

    IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-6833

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2020-6754

    Last Modified: 21 Nov 2024

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).

    Published: 5 Feb 2020
    7.8
    High

    CVE-2019-12180

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious Project. The same issue is present in the "Save Script" function, which is executed automatically when saving a project.

    Published: 5 Feb 2020
    8.1
    High

    CVE-2019-11516

    Last Modified: 21 Nov 2024

    An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Extended Inquiry Responses (EIRs) are improperly handled, which causes a heap-based buffer overflow during device inquiry. This overflow can be used to overwrite existing functions with arbitrary code. The Reserved for Future Use (RFU) bits are not discarded by eir_handleRx(), and are included in an EIR's length. Therefore, one can exceed the expected 240 bytes, which leads to a heap-based buffer overflow in eir_getReceivedEIR() called by bthci_event_SendInquiryResultEvent(). In order to exploit this bug, an attacker must repeatedly connect to the victim's device in a short amount of time from different source addresses. This will cause the victim's Bluetooth stack to resolve the device names and therefore allocate buffers with attacker-controlled data. Due to the heap corruption, the name will be eventually written to an attacker-controlled location, leading to a write-what-where condition.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7966

    Last Modified: 21 Nov 2024

    GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal.

    Published: 5 Feb 2020
    4.3
    Medium

    CVE-2020-7967

    Last Modified: 21 Nov 2024

    GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7968

    Last Modified: 21 Nov 2024

    GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7969

    Last Modified: 21 Nov 2024

    GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure.

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2020-7971

    Last Modified: 21 Nov 2024

    GitLab EE 11.0 and later through 12.7.2 allows XSS.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7972

    Last Modified: 21 Nov 2024

    GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

    Published: 5 Feb 2020
    6.1
    Medium

    CVE-2020-7973

    Last Modified: 21 Nov 2024

    GitLab through 12.7.2 allows XSS.

    Published: 5 Feb 2020
    5.3
    Medium

    CVE-2020-7974

    Last Modified: 21 Nov 2024

    GitLab EE 10.1 through 12.7.2 allows Information Disclosure.

    Published: 5 Feb 2020
    9.8
    Critical

    CVE-2020-6174

    Last Modified: 21 Nov 2024

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

    Published: 5 Feb 2020
    5.3
    Medium

    CVE-2020-7976

    Last Modified: 21 Nov 2024

    GitLab EE 12.4 and later through 12.7.2 has Incorrect Access Control.

    Published: 5 Feb 2020
    8.1
    High

    CVE-2013-0507

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability

    Published: 5 Feb 2020
    5.3
    Medium

    CVE-2020-7977

    Last Modified: 21 Nov 2024

    GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

    Published: 5 Feb 2020
    7.5
    High

    CVE-2020-7978

    Last Modified: 21 Nov 2024

    GitLab EE 12.6 and later through 12.7.2 allows Denial of Service.

    Published: 5 Feb 2020