CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-6039

    Last Modified: 21 Nov 2024

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

    Published: 13 Jan 2020
    7.5
    High

    CVE-2014-6038

    Last Modified: 21 Nov 2024

    Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

    Published: 13 Jan 2020
    7.2
    High

    CVE-2014-6059

    Last Modified: 21 Nov 2024

    WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability

    Published: 13 Jan 2020
    8.8
    High

    CVE-2020-6860

    Last Modified: 21 Nov 2024

    libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.

    Published: 13 Jan 2020
    6.1
    Medium

    CVE-2020-6848

    Last Modified: 21 Nov 2024

    Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI.

    Published: 13 Jan 2020
    7.5
    High

    CVE-2020-5390

    Last Modified: 21 Nov 2024

    PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.

    Published: 13 Jan 2020
    7.5
    High

    CVE-2020-6851

    Last Modified: 22 Sept 2026

    OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

    Published: 13 Jan 2020
    5.4
    Medium

    CVE-2020-6847

    Last Modified: 21 Nov 2024

    OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript.

    Published: 11 Jan 2020
    6.1
    Medium

    CVE-2019-20377

    Last Modified: 21 Nov 2024

    TopList before 2019-09-03 allows XSS via a title.

    Published: 11 Jan 2020
    6.1
    Medium

    CVE-2019-20378

    Last Modified: 21 Nov 2024

    ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.

    Published: 11 Jan 2020
    6.1
    Medium

    CVE-2019-20379

    Last Modified: 21 Nov 2024

    ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.

    Published: 11 Jan 2020
    9.8
    Critical

    CVE-2020-6838

    Last Modified: 21 Nov 2024

    In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.

    Published: 11 Jan 2020
    9.8
    Critical

    CVE-2020-6839

    Last Modified: 21 Nov 2024

    In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.

    Published: 11 Jan 2020
    9.8
    Critical

    CVE-2020-6840

    Last Modified: 21 Nov 2024

    In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

    Published: 11 Jan 2020
    9.8
    Critical

    CVE-2020-6836

    Last Modified: 21 Nov 2024

    grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.

    Published: 11 Jan 2020
    6.1
    Medium

    CVE-2019-19336

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

    Published: 11 Jan 2020
    8.8
    High

    CVE-2019-19475

    Last Modified: 21 Nov 2024

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system.

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2020-6835

    Last Modified: 21 Nov 2024

    An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.

    Published: 10 Jan 2020
    7.8
    High

    CVE-2012-4603

    Last Modified: 21 Nov 2024

    Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.

    Published: 10 Jan 2020
    4.3
    Medium

    CVE-2012-3821

    Last Modified: 21 Nov 2024

    A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2012-4284

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code

    Published: 10 Jan 2020
    5.4
    Medium

    CVE-2019-18588

    Last Modified: 21 Nov 2024

    Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users' sessions.

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2011-5020

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2019-14301

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).

    Published: 10 Jan 2020
    6.8
    Medium

    CVE-2019-14302

    Last Modified: 21 Nov 2024

    On Ricoh SP C250DN 1.06 devices, a debug port can be used.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2019-14306

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).

    Published: 10 Jan 2020
    8.8
    High

    CVE-2019-14304

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.06 devices allow CSRF.

    Published: 10 Jan 2020
    7.8
    High

    CVE-2019-18194

    Last Modified: 21 Nov 2024

    TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2012-4030

    Last Modified: 21 Nov 2024

    Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2012-3824

    Last Modified: 21 Nov 2024

    In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2012-3823

    Last Modified: 21 Nov 2024

    Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.

    Published: 10 Jan 2020
    7.5
    High

    CVE-2012-3822

    Last Modified: 21 Nov 2024

    Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.

    Published: 10 Jan 2020
    9.1
    Critical

    CVE-2020-6162

    Last Modified: 21 Nov 2024

    An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.

    Published: 10 Jan 2020
    5.3
    Medium

    CVE-2019-4559

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 166355.

    Published: 10 Jan 2020
    7.8
    High

    CVE-2019-4508

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.

    Published: 10 Jan 2020
    3.5
    Low

    CVE-2020-1767

    Last Modified: 21 Nov 2024

    Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue affects: ((OTRS)) Community Edition 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

    Published: 10 Jan 2020
    2
    Low

    CVE-2020-1766

    Last Modified: 21 Nov 2024

    Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

    Published: 10 Jan 2020
    3.5
    Low

    CVE-2020-1765

    Last Modified: 21 Nov 2024

    An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2014-5093

    Last Modified: 21 Nov 2024

    Status2k does not remove the install directory allowing credential reset.

    Published: 10 Jan 2020
    8.8
    High

    CVE-2014-5092

    Last Modified: 21 Nov 2024

    Status2k allows Remote Command Execution in admin/options/editpl.php.

    Published: 10 Jan 2020
    6.1
    Medium

    CVE-2011-4595

    Last Modified: 13 Feb 2025

    Pretty-Link WordPress plugin 1.5.2 has XSS

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2013-7380

    Last Modified: 21 Nov 2024

    The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability

    Published: 10 Jan 2020
    8.8
    High

    CVE-2013-6231

    Last Modified: 21 Nov 2024

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

    Published: 10 Jan 2020
    6.1
    Medium

    CVE-2014-4561

    Last Modified: 21 Nov 2024

    The ultimate-weather plugin 1.0 for WordPress has XSS

    Published: 10 Jan 2020
    6.1
    Medium

    CVE-2014-4530

    Last Modified: 21 Nov 2024

    flog plugin 0.1 for WordPress has XSS

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2014-4982

    Last Modified: 21 Nov 2024

    LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2014-5081

    Last Modified: 21 Nov 2024

    sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

    Published: 10 Jan 2020
    9.8
    Critical

    CVE-2014-4984

    Last Modified: 21 Nov 2024

    Déjà Vu Crescendo Sales CRM has remote SQL Injection

    Published: 10 Jan 2020
    6.5
    Medium

    CVE-2014-5011

    Last Modified: 21 Nov 2024

    DOMPDF before 0.6.2 allows Information Disclosure.

    Published: 10 Jan 2020
    6.5
    Medium

    CVE-2014-5012

    Last Modified: 21 Nov 2024

    DOMPDF before 0.6.2 allows denial of service.

    Published: 10 Jan 2020