CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2020-8118

    Last Modified: 21 Nov 2024

    An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-8119

    Last Modified: 21 Nov 2024

    Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2020-8120

    Last Modified: 21 Nov 2024

    A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.

    Published: 4 Feb 2020
    4.9
    Medium

    CVE-2020-8123

    Last Modified: 21 Nov 2024

    A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2020-8115

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printed back without proper escaping in a JavaScript context, allowing an attacker to execute arbitrary JS code on the browser of the victim.

    Published: 4 Feb 2020
    8.1
    High

    CVE-2020-8121

    Last Modified: 21 Nov 2024

    A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2020-8125

    Last Modified: 21 Nov 2024

    Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-8615

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).

    Published: 4 Feb 2020
    9.6
    Critical

    CVE-2019-10784

    Last Modified: 21 Nov 2024

    phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.

    Published: 4 Feb 2020
    7.2
    High

    CVE-2020-4163

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2019-4675

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.

    Published: 4 Feb 2020
    4.9
    Medium

    CVE-2019-4674

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2019-4562

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2019-4551

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 165953.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2019-4550

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2019-4548

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 165950.

    Published: 4 Feb 2020
    7.2
    High

    CVE-2019-4541

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2019-4540

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165813.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2019-4451

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163493.

    Published: 4 Feb 2020
    7.8
    High

    CVE-2019-19273

    Last Modified: 21 Nov 2024

    On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.

    Published: 4 Feb 2020
    8.1
    High

    CVE-2013-2678

    Last Modified: 21 Nov 2024

    Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

    Published: 4 Feb 2020
    5.4
    Medium

    CVE-2019-19968

    Last Modified: 21 Nov 2024

    PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Builder components. An authenticated user can inject dangerous content into a data store that is later read and included in dynamic content.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2013-2676

    Last Modified: 21 Nov 2024

    Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2013-7055

    Last Modified: 21 Nov 2024

    D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2013-7054

    Last Modified: 21 Nov 2024

    D-Link DIR-100 4.03B07: cli.cgi XSS

    Published: 4 Feb 2020
    8.8
    High

    CVE-2013-7053

    Last Modified: 21 Nov 2024

    D-Link DIR-100 4.03B07: cli.cgi CSRF

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2013-7052

    Last Modified: 21 Nov 2024

    D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

    Published: 4 Feb 2020
    8.8
    High

    CVE-2013-7051

    Last Modified: 21 Nov 2024

    D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2013-1422

    Last Modified: 21 Nov 2024

    webcalendar before 1.2.7 shows the reason for a failed login (e.g., "no such user").

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2012-5686

    Last Modified: 21 Nov 2024

    ZPanel 10.0.1 has insufficient entropy for its password reset process.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2011-4912

    Last Modified: 21 Nov 2024

    Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2012-5618

    Last Modified: 21 Nov 2024

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

    Published: 4 Feb 2020
    7.5
    High

    CVE-2011-3629

    Last Modified: 21 Nov 2024

    Joomla! core 1.7.1 allows information disclosure due to weak encryption

    Published: 4 Feb 2020
    7.5
    High

    CVE-2011-4937

    Last Modified: 21 Nov 2024

    Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

    Published: 4 Feb 2020
    6.1
    Medium

    CVE-2020-3939

    Last Modified: 21 Nov 2024

    SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal information may be leaked to attackers via the vulnerability.

    Published: 4 Feb 2020
    9.8
    Critical

    CVE-2020-3938

    Last Modified: 21 Nov 2024

    SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.

    Published: 4 Feb 2020
    8.1
    High

    CVE-2020-3937

    Last Modified: 21 Nov 2024

    SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-5235

    Last Modified: 21 Nov 2024

    There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLOC, the message to be decoded contains a repeated string, bytes or message field and realloc() runs out of memory when expanding the array nanopb can end up calling `free()` on a pointer value that comes from uninitialized memory. Depending on platform this can result in a crash or further memory corruption, which may be exploitable in some cases. This problem is fixed in nanopb-0.4.1, nanopb-0.3.9.5, nanopb-0.2.9.4.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6382

    Last Modified: 21 Nov 2024

    Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6388

    Last Modified: 21 Nov 2024

    Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6389

    Last Modified: 21 Nov 2024

    Out of bounds write in WebRTC in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted video stream.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-6392

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6395

    Last Modified: 21 Nov 2024

    Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 4 Feb 2020
    4.3
    Medium

    CVE-2020-6396

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6398

    Last Modified: 21 Nov 2024

    Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6404

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    6.5
    Medium

    CVE-2020-6408

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6409

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker who convinced the user to enter a URI to bypass navigation restrictions via a crafted domain name.

    Published: 4 Feb 2020
    8.8
    High

    CVE-2020-6416

    Last Modified: 21 Nov 2024

    Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Feb 2020
    5.3
    Medium

    CVE-2020-8124

    Last Modified: 21 Nov 2024

    Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

    Published: 4 Feb 2020