CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2019-20445

    Last Modified: 21 Nov 2024

    HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

    Published: 29 Jan 2020
    9.1
    Critical

    CVE-2019-20444

    Last Modified: 1 Jul 2025

    HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

    Published: 29 Jan 2020
    5.8
    Medium

    CVE-2020-2100

    Last Modified: 21 Nov 2024

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

    Published: 29 Jan 2020
    5.3
    Medium

    CVE-2020-7955

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise 1.4.1 through 1.6.2 did not uniformly enforce ACLs across all API endpoints, resulting in potential unintended information disclosure. Fixed in 1.6.3.

    Published: 29 Jan 2020
    8.1
    High

    CVE-2020-1931

    Last Modified: 21 Nov 2024

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue will throw warnings. Thanks to Damian Lukowski at credativ for reporting the issue ethically. With this bug unpatched, exploits can be injected in a number of scenarios though doing so remotely is difficult. In addition to upgrading to SA 3.4.4, we again recommend that users should only use update channels or 3rd party .cf files from trusted places.

    Published: 29 Jan 2020
    8.6
    High

    CVE-2020-2099

    Last Modified: 21 Nov 2024

    Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.

    Published: 29 Jan 2020
    5.3
    Medium

    CVE-2020-2102

    Last Modified: 21 Nov 2024

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2020-2103

    Last Modified: 21 Nov 2024

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

    Published: 29 Jan 2020
    4.3
    Medium

    CVE-2020-2104

    Last Modified: 21 Nov 2024

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2020-2105

    Last Modified: 21 Nov 2024

    REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

    Published: 29 Jan 2020
    5.3
    Medium

    CVE-2020-2101

    Last Modified: 21 Nov 2024

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.

    Published: 29 Jan 2020
    4.4
    Medium

    CVE-2020-5227

    Last Modified: 21 Nov 2024

    Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *feedgen* library allows supplying XML as content for some of the available fields. This XML will be parsed and integrated into the existing XML tree. During this process, feedgen is vulnerable to XML Denial of Service Attacks (e.g. XML Bomb). This becomes a concern in particular if feedgen is used to include content from untrused sources and if XML (including XHTML) is directly included instead of providing plain tex content only. This problem has been fixed in feedgen 0.9.0 which disallows XML entity expansion and external resources.

    Published: 28 Jan 2020
    5.4
    Medium

    CVE-2020-8426

    Last Modified: 21 Nov 2024

    The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-8424

    Last Modified: 21 Nov 2024

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2020-8425

    Last Modified: 21 Nov 2024

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2013-1603

    Last Modified: 21 Nov 2024

    An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5215

    Last Modified: 21 Nov 2024

    In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode. This issue can lead to denial of service in inference/training where a malicious attacker can send a data point which contains a string instead of a tf.float16 value. Similar effects can be obtained by manipulating saved models and checkpoints whereby replacing a scalar tf.float16 value with a scalar string will trigger this issue due to automatic conversions. This can be easily reproduced by tf.constant("hello", tf.float16), if eager execution is enabled. This issue is patched in TensorFlow 1.15.1 and 2.0.1 with this vulnerability patched. TensorFlow 2.1.0 was released after we fixed the issue, thus it is not affected. Users are encouraged to switch to TensorFlow 1.15.1, 2.0.1 or 2.1.0.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2013-1602

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.0, DCS-7410 1.0, DCS-7510 1.0, and WCS-1100 1.02, which could let a malicious user obtain unauthorized access to video streams.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-8419

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2020-8421

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-8420

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2013-1601

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03, which could let a malicious user obtain sensitive information. which could let a malicious user obtain sensitive information.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-3214

    Last Modified: 21 Nov 2024

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

    Published: 28 Jan 2020
    8.1
    High

    CVE-2013-3212

    Last Modified: 21 Nov 2024

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-8417

    Last Modified: 21 Nov 2024

    The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2013-1600

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive information.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2013-3093

    Last Modified: 21 Nov 2024

    ASUS RT-N56U devices allow CSRF.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2013-3074

    Last Modified: 21 Nov 2024

    NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-3071

    Last Modified: 21 Nov 2024

    NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2013-2764

    Last Modified: 21 Nov 2024

    Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-1599

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-2748

    Last Modified: 21 Nov 2024

    Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2013-2714

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2014-8490

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary web script or HTML via the pid parameter to index.cfm.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2015-5483

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2020-4207

    Last Modified: 21 Nov 2024

    IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service. IBM X-Force ID: 174972.

    Published: 28 Jan 2020
    7.1
    High

    CVE-2019-4707

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.

    Published: 28 Jan 2020
    4.3
    Medium

    CVE-2019-4679

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force ID: 171515.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2019-4639

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.

    Published: 28 Jan 2020
    3.7
    Low

    CVE-2019-4638

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.

    Published: 28 Jan 2020
    4.3
    Medium

    CVE-2019-4637

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043.

    Published: 28 Jan 2020
    2.7
    Low

    CVE-2019-4636

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messages. IBM X-Force ID: 170013.

    Published: 28 Jan 2020
    2.7
    Low

    CVE-2019-4635

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.

    Published: 28 Jan 2020
    4.3
    Medium

    CVE-2019-4633

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2019-4632

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170004.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2019-4631

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 170001.

    Published: 28 Jan 2020
    7.8
    High

    CVE-2019-4620

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2019-4614

    Last Modified: 21 Nov 2024

    IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639.

    Published: 28 Jan 2020
    5.9
    Medium

    CVE-2019-4568

    Last Modified: 21 Nov 2024

    IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.

    Published: 28 Jan 2020
    5.4
    Medium

    CVE-2019-17338

    Last Modified: 21 Nov 2024

    The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that theoretically allow authenticated users to perform persistent cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Patterns - Search: versions 5.4.0 and below.

    Published: 28 Jan 2020