CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2019-11265

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11266

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11263

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11260

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11258

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11256

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    —
    Unknown

    CVE-2019-11257

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019

    Published: 3 Feb 2020
    5.5
    Medium

    CVE-2019-19119

    Last Modified: 21 Nov 2024

    An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.

    Published: 3 Feb 2020
    5.3
    Medium

    CVE-2013-2631

    Last Modified: 21 Nov 2024

    TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.

    Published: 3 Feb 2020
    5.3
    Medium

    CVE-2013-2624

    Last Modified: 21 Nov 2024

    Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2013-2623

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2013-2622

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the "selected_theme" parameter in error.php.

    Published: 3 Feb 2020
    4.3
    Medium

    CVE-2020-7993

    Last Modified: 21 Nov 2024

    Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2013-2621

    Last Modified: 21 Nov 2024

    Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.

    Published: 3 Feb 2020
    5.3
    Medium

    CVE-2014-8328

    Last Modified: 21 Nov 2024

    The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2019-18193

    Last Modified: 21 Nov 2024

    In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 and 5.0.013.0.

    Published: 3 Feb 2020
    8.3
    High

    CVE-2020-3927

    Last Modified: 21 Nov 2024

    An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2020-3926

    Last Modified: 21 Nov 2024

    An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.

    Published: 3 Feb 2020
    8.3
    High

    CVE-2020-3925

    Last Modified: 21 Nov 2024

    A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8508

    Last Modified: 21 Nov 2024

    nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-8597

    Last Modified: 3 Dec 2025

    eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

    Published: 3 Feb 2020
    4.7
    Medium

    CVE-2019-10146

    Last Modified: 21 Nov 2024

    A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.

    Published: 3 Feb 2020
    4.3
    Medium

    CVE-2019-10179

    Last Modified: 21 Nov 2024

    A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.

    Published: 3 Feb 2020
    2.4
    Low

    CVE-2019-10180

    Last Modified: 21 Nov 2024

    A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.

    Published: 3 Feb 2020
    5.7
    Medium

    CVE-2020-5236

    Last Modified: 21 Nov 2024

    Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like "Bad-header: xxxxxxxxxxxxxxx\x10" is received, it will cause the regular expression engine to catastrophically backtrack causing the process to use 100% CPU time and blocking any other interactions. This allows an attacker to send a single request with an invalid header and take the service offline. This issue was introduced in version 1.4.2 when the regular expression was updated to attempt to match the behaviour required by errata associated with RFC7230. The regular expression that is used to validate incoming headers has been updated in version 1.4.3, it is recommended that people upgrade to the new version of Waitress as soon as possible.

    Published: 3 Feb 2020
    7.5
    High

    CVE-2020-8449

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

    Published: 3 Feb 2020
    7
    High

    CVE-2020-0030

    Last Modified: 21 Nov 2024

    In binder_thread_release of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145286050References: Upstream kernel

    Published: 3 Feb 2020
    4.6
    Medium

    CVE-2020-1696

    Last Modified: 21 Nov 2024

    A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.

    Published: 3 Feb 2020
    7.3
    High

    CVE-2020-8450

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2020-1721

    Last Modified: 21 Nov 2024

    A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.

    Published: 3 Feb 2020
    9.8
    Critical

    CVE-2020-7471

    Last Modified: 21 Nov 2024

    Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

    Published: 3 Feb 2020
    4.6
    Medium

    CVE-2019-10178

    Last Modified: 21 Nov 2024

    It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, enabling a Stored Cross Site Scripting (XSS) vulnerability. An unauthenticated attacker could trick an authenticated victim into creating a specially crafted activity, which would execute arbitrary JavaScript code when viewed in a browser. All versions of pki-core are believed to be vulnerable.

    Published: 3 Feb 2020
    4.3
    Medium

    CVE-2019-10221

    Last Modified: 21 Nov 2024

    A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attacker could abuse this flaw to trick an authenticated user into clicking a specially crafted link which can execute arbitrary code when viewed in a browser.

    Published: 3 Feb 2020
    6.1
    Medium

    CVE-2020-8514

    Last Modified: 21 Nov 2024

    An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality.

    Published: 2 Feb 2020
    5.3
    Medium

    CVE-2020-8516

    Last Modified: 21 Nov 2024

    The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability

    Published: 2 Feb 2020
    7.5
    High

    CVE-2019-12528

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

    Published: 2 Feb 2020
    6.5
    Medium

    CVE-2019-20446

    Last Modified: 21 Nov 2024

    In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.

    Published: 2 Feb 2020
    7.5
    High

    CVE-2020-8517

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy.

    Published: 2 Feb 2020
    8.8
    High

    CVE-2020-9308

    Last Modified: 21 Nov 2024

    archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.

    Published: 2 Feb 2020
    9.8
    Critical

    CVE-2020-8515

    Last Modified: 7 Nov 2025

    DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

    Published: 1 Feb 2020
    6.1
    Medium

    CVE-2020-8512

    Last Modified: 21 Nov 2024

    In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.

    Published: 31 Jan 2020
    9.8
    Critical

    CVE-2014-2025

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

    Published: 31 Jan 2020
    6.1
    Medium

    CVE-2014-3809

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

    Published: 31 Jan 2020
    9.6
    Critical

    CVE-2014-5039

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Jan 2020
    6.1
    Medium

    CVE-2014-8338

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter.

    Published: 31 Jan 2020
    6.1
    Medium

    CVE-2013-3565

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.

    Published: 31 Jan 2020
    6.5
    Medium

    CVE-2020-8504

    Last Modified: 21 Nov 2024

    School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

    Published: 31 Jan 2020