CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2014-5013

    Last Modified: 21 Nov 2024

    DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

    Published: 10 Jan 2020
    6.1
    Medium

    CVE-2019-20375

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.

    Published: 10 Jan 2020
    6.1
    Medium

    CVE-2019-20376

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.

    Published: 10 Jan 2020
    5.5
    Medium

    CVE-2020-19724

    Last Modified: 21 Nov 2024

    A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.

    Published: 10 Jan 2020
    9.6
    Critical

    CVE-2019-20374

    Last Modified: 21 Nov 2024

    A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.

    Published: 9 Jan 2020
    7.8
    High

    CVE-2019-20373

    Last Modified: 21 Nov 2024

    LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-session script.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2020-6756

    Last Modified: 21 Nov 2024

    languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2020-6758

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Option/optionsAll.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows remote attackers to inject arbitrary web script or HTML via the ContentFrame parameter.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2020-6757

    Last Modified: 21 Nov 2024

    contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2020-5504

    Last Modified: 16 Apr 2025

    In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

    Published: 9 Jan 2020
    7.5
    High

    CVE-2012-3810

    Last Modified: 21 Nov 2024

    Samsung Kies before 2.5.0.12094_27_11 has registry modification.

    Published: 9 Jan 2020
    7.5
    High

    CVE-2012-3809

    Last Modified: 21 Nov 2024

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

    Published: 9 Jan 2020
    7.5
    High

    CVE-2012-3808

    Last Modified: 21 Nov 2024

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2012-3807

    Last Modified: 21 Nov 2024

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18969

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-5207

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18961

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18962

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18963

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18964

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18965

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18966

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18967

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18968

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-18970

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-5205

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-5206

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-5208

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-5209

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 9 Jan 2020
    7.5
    High

    CVE-2012-3806

    Last Modified: 21 Nov 2024

    Samsung Kies before 2.5.0.12094_27_11 contains a NULL pointer dereference vulnerability which could allow remote attackers to perform a denial of service.

    Published: 9 Jan 2020
    6.5
    Medium

    CVE-2019-20178

    Last Modified: 21 Nov 2024

    Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2019-20179

    Last Modified: 21 Nov 2024

    SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.

    Published: 9 Jan 2020
    7.2
    High

    CVE-2019-20183

    Last Modified: 21 Nov 2024

    uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.

    Published: 9 Jan 2020
    4.8
    Medium

    CVE-2019-20181

    Last Modified: 21 Nov 2024

    The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.

    Published: 9 Jan 2020
    7.8
    High

    CVE-2019-20184

    Last Modified: 21 Nov 2024

    KeePass 2.4.1 allows CSV injection in the title field of a CSV export.

    Published: 9 Jan 2020
    8.1
    High

    CVE-2012-2950

    Last Modified: 21 Nov 2024

    Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.

    Published: 9 Jan 2020
    4.8
    Medium

    CVE-2019-20182

    Last Modified: 21 Nov 2024

    The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.

    Published: 9 Jan 2020
    7.2
    High

    CVE-2012-2931

    Last Modified: 21 Nov 2024

    PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.

    Published: 9 Jan 2020
    4.8
    Medium

    CVE-2012-5558

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2012-4434

    Last Modified: 21 Nov 2024

    fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2012-2226

    Last Modified: 21 Nov 2024

    Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2012-1915

    Last Modified: 21 Nov 2024

    EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2019-18859

    Last Modified: 21 Nov 2024

    Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.

    Published: 9 Jan 2020
    7.6
    High

    CVE-2020-6168

    Last Modified: 21 Nov 2024

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2012-2714

    Last Modified: 21 Nov 2024

    The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.

    Published: 9 Jan 2020
    5.4
    Medium

    CVE-2020-6166

    Last Modified: 21 Nov 2024

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.

    Published: 9 Jan 2020
    5.3
    Medium

    CVE-2012-2724

    Last Modified: 21 Nov 2024

    The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2012-1261

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2012-1260

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remote attackers to inject arbitrary web script or HTML via the newUser parameter. NOTE: this might not be a vulnerability, since an administrator might already have the privileges to create arbitrary script.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2012-1259

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to cgi-bin/scrut_fa_exclusions.cgi, (2) getPermissionsAndPreferences parameter to cgi-bin/login.cgi, or (3) possibly certain parameters to d4d/alarms.php as demonstrated by the search_str parameter.

    Published: 9 Jan 2020