CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-7109

    Last Modified: 21 Nov 2024

    The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.

    Published: 22 Jan 2020
    7.2
    High

    CVE-2011-3611

    Last Modified: 21 Nov 2024

    A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

    Published: 22 Jan 2020
    6.1
    Medium

    CVE-2011-3610

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.

    Published: 22 Jan 2020
    5.4
    Medium

    CVE-2011-3595

    Last Modified: 21 Nov 2024

    Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

    Published: 22 Jan 2020
    8.8
    High

    CVE-2011-3582

    Last Modified: 21 Nov 2024

    A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2020-6960

    Last Modified: 21 Nov 2024

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch contain an SQL injection vulnerability that could give an attacker remote unauthenticated access to the web user interface with administrator-level privileges.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2020-6959

    Last Modified: 21 Nov 2024

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR PE prior to Version NVR 5.6 Build 595 T2-Patch, and MPNVRSWXX prior to Version NVR 5.6 Build 595 T2-Patch are vulnerable to an unsafe deserialization of untrusted data. An attacker may be able to remotely modify deserialized data without authentication using a specially crafted web request, resulting in remote code execution.

    Published: 22 Jan 2020
    5.4
    Medium

    CVE-2020-7228

    Last Modified: 21 Nov 2024

    The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.

    Published: 22 Jan 2020
    —
    Unknown

    CVE-2019-18586

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 22 Jan 2020
    —
    Unknown

    CVE-2019-18585

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 22 Jan 2020
    —
    Unknown

    CVE-2019-18584

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 22 Jan 2020
    —
    Unknown

    CVE-2019-18583

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 22 Jan 2020
    7.8
    High

    CVE-2019-6858

    Last Modified: 21 Nov 2024

    A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2019-10781

    Last Modified: 21 Nov 2024

    In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2019-10780

    Last Modified: 21 Nov 2024

    BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2018-16272

    Last Modified: 21 Nov 2024

    The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    6.5
    Medium

    CVE-2018-16271

    Last Modified: 21 Nov 2024

    The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    7.5
    High

    CVE-2018-16270

    Last Modified: 21 Nov 2024

    Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.

    Published: 22 Jan 2020
    7.5
    High

    CVE-2018-16269

    Last Modified: 21 Nov 2024

    The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    4.3
    Medium

    CVE-2018-16268

    Last Modified: 21 Nov 2024

    The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    8.1
    High

    CVE-2018-16267

    Last Modified: 21 Nov 2024

    The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    6.5
    Medium

    CVE-2018-16265

    Last Modified: 21 Nov 2024

    The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    6.5
    Medium

    CVE-2018-16264

    Last Modified: 21 Nov 2024

    The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    8.8
    High

    CVE-2018-16263

    Last Modified: 21 Nov 2024

    The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    8.8
    High

    CVE-2018-16262

    Last Modified: 21 Nov 2024

    The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy configurations. Such actions include installing, decrypting, and killing other packages. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    8.1
    High

    CVE-2018-16266

    Last Modified: 21 Nov 2024

    The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

    Published: 22 Jan 2020
    9.8
    Critical

    CVE-2011-4943

    Last Modified: 21 Nov 2024

    ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)

    Published: 22 Jan 2020
    6.5
    Medium

    CVE-2019-12490

    Last Modified: 21 Nov 2024

    An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.

    Published: 22 Jan 2020
    6.9
    Medium

    CVE-2019-16791

    Last Modified: 21 Nov 2024

    In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.

    Published: 22 Jan 2020
    6.1
    Medium

    CVE-2018-17981

    Last Modified: 21 Nov 2024

    Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.

    Published: 22 Jan 2020
    4.4
    Medium

    CVE-2020-5216

    Last Modified: 21 Nov 2024

    In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seeing a newline in the header, rails will silently create a new Content-Security-Policy header with the remaining value of the original string. It will continue to create new headers for each newline. This has been fixed in 6.3.0, 5.2.0, and 3.9.0.

    Published: 22 Jan 2020
    4.4
    Medium

    CVE-2020-5217

    Last Modified: 21 Nov 2024

    In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon could be injected leading to directive injection. This could be used to e.g. override a script-src directive. Duplicate directives are ignored and the first one wins. The directives in secure_headers are sorted alphabetically so they pretty much all come before script-src. A previously undefined directive would receive a value even if SecureHeaders::OPT_OUT was supplied. The fixed versions will silently convert the semicolons to spaces and emit a deprecation warning when this happens. This will result in innocuous browser console messages if being exploited/accidentally used. In future releases, we will raise application errors resulting in 500s. Depending on what major version you are using, the fixed versions are 6.2.0, 5.1.0, 3.8.0.

    Published: 22 Jan 2020
    8.8
    High

    CVE-2016-4761

    Last Modified: 21 Nov 2024

    WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS

    Published: 22 Jan 2020
    7.5
    High

    CVE-2019-19414

    Last Modified: 21 Nov 2024

    There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.

    Published: 21 Jan 2020
    7.5
    High

    CVE-2019-19413

    Last Modified: 21 Nov 2024

    There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.

    Published: 21 Jan 2020
    5.5
    Medium

    CVE-2020-1788

    Last Modified: 21 Nov 2024

    Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure.

    Published: 21 Jan 2020
    7.5
    High

    CVE-2019-19886

    Last Modified: 3 Jul 2025

    Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.

    Published: 21 Jan 2020
    7.2
    High

    CVE-2020-7594

    Last Modified: 21 Nov 2024

    MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.

    Published: 21 Jan 2020
    8.2
    High

    CVE-2019-18426

    Last Modified: 24 Oct 2025

    A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

    Published: 21 Jan 2020
    8.1
    High

    CVE-2020-7040

    Last Modified: 21 Nov 2024

    storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file.)

    Published: 21 Jan 2020
    —
    Unknown

    CVE-2020-5498

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Jan 2020
    7.5
    High

    CVE-2020-6638

    Last Modified: 21 Nov 2024

    Grin through 2.1.1 has Insufficient Validation.

    Published: 21 Jan 2020
    7.5
    High

    CVE-2019-17584

    Last Modified: 21 Nov 2024

    The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The private key is also used in an internal interface of another Meinberg Device and can be extracted from a firmware update of this device. An update to fix the vulnerability was published by the vendor.

    Published: 21 Jan 2020
    6.5
    Medium

    CVE-2019-17357

    Last Modified: 21 Nov 2024

    Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.

    Published: 21 Jan 2020
    8.8
    High

    CVE-2020-6849

    Last Modified: 21 Nov 2024

    The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.

    Published: 21 Jan 2020
    6.1
    Medium

    CVE-2019-19592

    Last Modified: 21 Nov 2024

    Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting

    Published: 21 Jan 2020
    9.8
    Critical

    CVE-2016-11018

    Last Modified: 21 Nov 2024

    An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

    Published: 21 Jan 2020
    —
    Unknown

    CVE-2019-5707

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 21 Jan 2020
    —
    Unknown

    CVE-2019-5704

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 21 Jan 2020
    —
    Unknown

    CVE-2019-5705

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 21 Jan 2020