CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2015-0949

    Last Modified: 21 Nov 2024

    The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, which allows local users to bypass the Secure Boot protection mechanism and gain privileges by leveraging write access to physical memory.

    Published: 30 Jan 2020
    6.5
    Medium

    CVE-2013-4187

    Last Modified: 21 Nov 2024

    The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2013-2198

    Last Modified: 21 Nov 2024

    The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-2294

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-4241

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2012-6133

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

    Published: 30 Jan 2020
    7.7
    High

    CVE-2020-5229

    Last Modified: 21 Nov 2024

    Opencast before 8.1 stores passwords using the rather outdated and cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of a random salt, causing hashes for users with the same username and password to collide which is problematic especially for popular users like the default `admin` user. This essentially means that for an attacker, it might be feasible to reconstruct a user's password given access to these hashes. Note that attackers needing access to the hashes means that they must gain access to the database in which these are stored first to be able to start cracking the passwords. The problem is addressed in Opencast 8.1 which now uses the modern and much stronger bcrypt password hashing algorithm for storing passwords. Note, that old hashes remain MD5 until the password is updated. For a list of users whose password hashes are stored using MD5, take a look at the `/user-utils/users/md5.json` REST endpoint.

    Published: 30 Jan 2020
    7.6
    High

    CVE-2020-5228

    Last Modified: 21 Nov 2024

    Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of users to protect media. This leads to users unknowingly handing out public access to events without their knowledge. The problem has been addressed in Opencast 7.6 and 8.1 where the OAI-PMH endpoint is configured to require users with `ROLE_ADMIN` by default. In addition to this, Opencast 9 removes the OAI-PMH publication from the default workflow, making the publication a conscious decision users have to make by updating their workflows.

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2014-3719

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2014-3718

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid parameter.

    Published: 30 Jan 2020
    6.2
    Medium

    CVE-2019-3016

    Last Modified: 21 Nov 2024

    In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from another process in the same guest. This problem is limit to the host running linux kernel 4.10 with a guest running linux kernel 4.16 or later. The problem mainly affects AMD processors but Intel CPUs cannot be ruled out.

    Published: 30 Jan 2020
    6.5
    Medium

    CVE-2019-17273

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in IPv6 environments.

    Published: 30 Jan 2020
    5.9
    Medium

    CVE-2020-5233

    Last Modified: 21 Nov 2024

    OAuth2 Proxy before 5.0 has an open redirect vulnerability. Authentication tokens could be silently harvested by an attacker. This has been patched in version 5.0.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2020-7913

    Last Modified: 21 Nov 2024

    JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

    Published: 30 Jan 2020
    5.3
    Medium

    CVE-2020-7912

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2020-7911

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.2, several user-level pages were vulnerable to XSS.

    Published: 30 Jan 2020
    5.4
    Medium

    CVE-2020-7910

    Last Modified: 21 Nov 2024

    JetBrains TeamCity before 2019.2 was vulnerable to a stored XSS attack by a user with the developer role.

    Published: 30 Jan 2020
    7.5
    High

    CVE-2020-7909

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.

    Published: 30 Jan 2020
    4.3
    Medium

    CVE-2020-7908

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.

    Published: 30 Jan 2020
    7.5
    High

    CVE-2020-7906

    Last Modified: 21 Nov 2024

    In JetBrains Rider versions 2019.3 EAP2 through 2019.3 EAP7, there were unsigned binaries provided by the Windows installer. This issue was fixed in release version 2019.3.

    Published: 30 Jan 2020
    7.5
    High

    CVE-2020-7905

    Last Modified: 21 Nov 2024

    Ports listened to by JetBrains IntelliJ IDEA before 2019.3 were exposed to the network.

    Published: 30 Jan 2020
    7.4
    High

    CVE-2020-7904

    Last Modified: 21 Nov 2024

    In JetBrains IntelliJ IDEA before 2019.3, some Maven repositories were accessed via HTTP instead of HTTPS.

    Published: 30 Jan 2020
    6.8
    Medium

    CVE-2019-20050

    Last Modified: 21 Nov 2024

    Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extension is disabled on the host system. The attacker must include shell metacharacters in the content type.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-0739

    Last Modified: 21 Nov 2024

    Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-0738

    Last Modified: 21 Nov 2024

    Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.

    Published: 30 Jan 2020
    5.3
    Medium

    CVE-2013-1631

    Last Modified: 21 Nov 2024

    Verax NMS prior to 2.1.0 leaks connection details when any user executes a Repair Table action

    Published: 30 Jan 2020
    7.5
    High

    CVE-2013-1352

    Last Modified: 21 Nov 2024

    Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.

    Published: 30 Jan 2020
    5.9
    Medium

    CVE-2013-1351

    Last Modified: 21 Nov 2024

    Verax NMS prior to 2.10 allows authentication via the encrypted password without knowing the cleartext password.

    Published: 30 Jan 2020
    9.1
    Critical

    CVE-2013-1350

    Last Modified: 21 Nov 2024

    Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-1867

    Last Modified: 21 Nov 2024

    Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2013-1866

    Last Modified: 21 Nov 2024

    OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability

    Published: 30 Jan 2020
    7.8
    High

    CVE-2013-0725

    Last Modified: 21 Nov 2024

    ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities

    Published: 30 Jan 2020
    7.5
    High

    CVE-2013-0291

    Last Modified: 21 Nov 2024

    NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

    Published: 30 Jan 2020
    8.8
    High

    CVE-2020-8442

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2020-8443

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2020-8444

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2020-8445

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

    Published: 30 Jan 2020
    5.5
    Medium

    CVE-2020-8446

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local user.

    Published: 30 Jan 2020
    9.8
    Critical

    CVE-2020-8447

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

    Published: 30 Jan 2020
    5.5
    Medium

    CVE-2020-8448

    Last Modified: 21 Nov 2024

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd UNIX domain socket by a local user.

    Published: 30 Jan 2020
    6.1
    Medium

    CVE-2020-8647

    Last Modified: 21 Nov 2024

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.

    Published: 30 Jan 2020
    6.5
    Medium

    CVE-2020-8492

    Last Modified: 21 Nov 2024

    Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

    Published: 30 Jan 2020
    5.9
    Medium

    CVE-2020-8649

    Last Modified: 21 Nov 2024

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8460

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8459

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8458

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8457

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8456

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8455

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8454

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020