CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-15585

    Last Modified: 21 Nov 2024

    Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2019-5462

    Last Modified: 21 Nov 2024

    A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2019-15586

    Last Modified: 21 Nov 2024

    A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

    Published: 28 Jan 2020
    5.4
    Medium

    CVE-2019-15607

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.

    Published: 28 Jan 2020
    5.4
    Medium

    CVE-2019-17651

    Last Modified: 21 Nov 2024

    An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2020-1932

    Last Modified: 21 Nov 2024

    An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2020-1933

    Last Modified: 21 Nov 2024

    A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2020-1928

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal values entered in a sensitive property when no parameter was present.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2019-10770

    Last Modified: 21 Nov 2024

    All versions of io.ratpack:ratpack-core from 0.9.10 inclusive and before 1.7.6 are vulnerable to Cross-site Scripting (XSS). This affects the development mode error handler when an exception message contains untrusted data. Note the production mode error handler is not vulnerable - so for this to be utilized in production it would require users to not disable development mode.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2019-10779

    Last Modified: 21 Nov 2024

    All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom UI via an XSS vulnerability to take full control of the Stroom UI on behalf of the logged-in user.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2020-7219

    Last Modified: 21 Nov 2024

    HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2020-7919

    Last Modified: 21 Nov 2024

    Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

    Published: 28 Jan 2020
    7.3
    High

    CVE-2020-8116

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

    Published: 28 Jan 2020
    7.1
    High

    CVE-2020-8428

    Last Modified: 21 Nov 2024

    fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an open system call for a UNIX domain socket, if the socket is being moved to a new parent directory and its old parent directory is being removed.

    Published: 28 Jan 2020
    4.8
    Medium

    CVE-2019-20434

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Datasource creation page of the Management Console.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20435

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A reflected XSS attack could be performed in the inline API documentation editor page of the API Publisher by sending an HTTP GET request with a harmful docName request parameter.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2019-20437

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a custom claim dialect with an XSS payload is configured in the identity provider basic claim configuration, that payload gets executed, if a user picks up that dialect's URI as the provisioning claim in the advanced claim configuration of the same Identity Provider. The attacker also needs to have privileges to log in to the management console, and to add and update identity provider configurations.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20438

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been identified in the inline API documentation editor page of the API Publisher.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20439

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in defining a scope in the "manage the API" page of the API Publisher.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20440

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the update API documentation feature of the API Publisher.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20441

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0. A potential Stored Cross-Site Scripting (XSS) vulnerability has been identified in the 'implement phase' of the API Publisher.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20442

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in roleToAuthorize has been identified in the registry UI.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-20443

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0, WSO2 Enterprise Integrator 6.5.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. A potential stored Cross-Site Scripting (XSS) vulnerability in mediaType has been identified in the registry UI.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2019-20436

    Last Modified: 21 Nov 2024

    An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. If there is a claim dialect configured with an XSS payload in the dialect URI, and a user picks up this dialect's URI and adds it as the service provider claim dialect while configuring the service provider, that payload gets executed. The attacker also needs to have privileges to log in to the management console, and to add and configure claim dialects.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2019-7131

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier version, and 2015.006.30461 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2019-8257

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 27 Jan 2020
    7.8
    High

    CVE-2019-13519

    Last Modified: 17 Dec 2024

    A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

    Published: 27 Jan 2020
    7.8
    High

    CVE-2019-13521

    Last Modified: 17 Dec 2024

    A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2013-2612

    Last Modified: 21 Nov 2024

    Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.

    Published: 27 Jan 2020
    7.5
    High

    CVE-2013-2499

    Last Modified: 21 Nov 2024

    SimpleHRM 2.3 and earlier could allow remote attackers to bypass the authentication process in 'user_manager.php' via spoofing a cookie.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2020-8091

    Last Modified: 21 Nov 2024

    svg.swf in TYPO3 6.2.0 to 6.2.38 ELTS and 7.0.0 to 7.1.0 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. This may be at a contrib/websvg/svg.swf pathname.

    Published: 27 Jan 2020
    7.5
    High

    CVE-2013-2474

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.

    Published: 27 Jan 2020
    7.2
    High

    CVE-2013-2267

    Last Modified: 21 Nov 2024

    PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2020-8090

    Last Modified: 21 Nov 2024

    The Username field in the Storage Service settings of A1 WLAN Box ADB VV2220v2 devices allows stored XSS (after a successful Administrator login).

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2012-6448

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jan 2020
    4.4
    Medium

    CVE-2020-5218

    Last Modified: 21 Nov 2024

    Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if no sylius_channel.debug is set explicitly in the configuration, the default value which is kernel.debug will be not resolved and cast to boolean, enabling this debug feature even if that parameter is set to false. Patch has been provided for Sylius 1.3.x and newer - 1.3.16, 1.4.12, 1.5.9, 1.6.5. Versions older than 1.3 are not covered by our security support anymore.

    Published: 27 Jan 2020
    4.4
    Medium

    CVE-2020-5220

    Last Modified: 21 Nov 2024

    Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with ResourceBundle's controller is affected. The vulnerable versions are: <1.3 || >=1.3.0 <=1.3.12 || >=1.4.0 <=1.4.5 || >=1.5.0 <=1.5.0 || >=1.6.0 <=1.6.2. The patch is provided for Sylius ResourceBundle 1.3.13, 1.4.6, 1.5.1 and 1.6.3, but not for any versions below 1.3.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2020-8088

    Last Modified: 21 Nov 2024

    panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2020-8087

    Last Modified: 21 Nov 2024

    SMC Networks D3G0804W D3GNV5M-3.5.1.6.10_GA devices allow remote command execution by leveraging access to the Network Diagnostic Tools screen, as demonstrated by an admin login. The attacker must use a Parameter Pollution approach against goform/formSetDiagnosticToolsFmPing by providing the vlu_diagnostic_tools__ping_address parameter twice: once with a shell metacharacter and a command name, and once with a command argument.

    Published: 27 Jan 2020
    5.4
    Medium

    CVE-2020-5207

    Last Modified: 21 Nov 2024

    In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

    Published: 27 Jan 2020
    7
    High

    CVE-2019-11288

    Last Modified: 21 Nov 2024

    In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x versions prior to 8.5.47.A, and 9.x versions prior to 9.0.27.A, when a tc Runtime instance is configured with the JMX Socket Listener, a local attacker without access to the tc Runtime process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the tc Runtime instance.

    Published: 27 Jan 2020
    9.8
    Critical

    CVE-2014-8563

    Last Modified: 21 Nov 2024

    Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2019-8945

    Last Modified: 21 Nov 2024

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2019-8946

    Last Modified: 21 Nov 2024

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains persistent XSS.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2019-8947

    Last Modified: 21 Nov 2024

    Zimbra Collaboration 8.7.x - 8.8.11P2 contains non-persistent XSS.

    Published: 27 Jan 2020
    4.7
    Medium

    CVE-2018-19441

    Last Modified: 21 Nov 2024

    An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authentication/authorization. If an attacker knows the serial number and is able to estimate the time of first provisioning of a robot, he is able to brute force the generated secret_key of the robot. This is because the entropy of the secret_key exclusively relies on these two values, due to not seeding the random generator and using several constant inputs for secret_key computation. Serial numbers are printed on the packaging and equal the MAC address of the robot.

    Published: 27 Jan 2020
    5.4
    Medium

    CVE-2015-2249

    Last Modified: 21 Nov 2024

    Zimbra Collaboration before 8.6.0 patch5 has XSS.

    Published: 27 Jan 2020
    6.1
    Medium

    CVE-2014-5500

    Last Modified: 21 Nov 2024

    Synacor Zimbra Collaboration before 8.0.8 has XSS.

    Published: 27 Jan 2020
    5.4
    Medium

    CVE-2019-11318

    Last Modified: 21 Nov 2024

    Zimbra Collaboration before 8.8.12 Patch 1 has persistent XSS.

    Published: 27 Jan 2020
    4.8
    Medium

    CVE-2019-12427

    Last Modified: 21 Nov 2024

    Zimbra Collaboration before 8.8.15 Patch 1 is vulnerable to a non-persistent XSS via the Admin Console.

    Published: 27 Jan 2020