CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2014-1850

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3743. Reason: This candidate is a duplicate of CVE-2014-3743. Notes: All CVE users should reference CVE-2014-3743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usag

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-16717

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.2 has XSS.

    Published: 6 Jan 2020
    8.8
    High

    CVE-2019-19509

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.

    Published: 6 Jan 2020
    7.8
    High

    CVE-2019-19585

    Last Modified: 21 Nov 2024

    An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apache configuration" update, apache has high privileges for some binaries. This can be exploited by an attacker to bypass local security restrictions.

    Published: 6 Jan 2020
    6.8
    Medium

    CVE-2020-5512

    Last Modified: 21 Nov 2024

    Gila CMS 1.11.8 allows /admin/media?path=../ Path Traversal.

    Published: 6 Jan 2020
    6.5
    Medium

    CVE-2020-5204

    Last Modified: 21 Nov 2024

    In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being filled via sprintf() with user input based on the format specifier string %d.%d.%d.%d. The 16 byte size is correct for valid IPv4 addresses (len('255.255.255.255') == 16), but the format specifier %d allows more than 3 digits. This has been fixed in version 2.11

    Published: 6 Jan 2020
    6.8
    Medium

    CVE-2020-5513

    Last Modified: 21 Nov 2024

    Gila CMS 1.11.8 allows /cm/delete?t=../ Directory Traversal.

    Published: 6 Jan 2020
    9.1
    Critical

    CVE-2020-5514

    Last Modified: 21 Nov 2024

    Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

    Published: 6 Jan 2020
    5.4
    Medium

    CVE-2015-4039

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2020-5515

    Last Modified: 21 Nov 2024

    Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3473

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3472

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3471

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3470

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3469

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-3468

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 6 Jan 2020
    9.1
    Critical

    CVE-2019-18792

    Last Modified: 21 Nov 2024

    An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK packet (containing the data) will be ignored by Suricata because it overlaps the FIN packet (the sequence and ack number are identical in the two packets). The client will ignore the fake FIN packet because the ACK flag is not set. Both linux and windows clients are ignoring the injected packet.

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-19864

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-19863

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-19862

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-19861

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2019-17568

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 6 Jan 2020
    7.8
    High

    CVE-2019-9468

    Last Modified: 21 Nov 2024

    In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-139683471

    Published: 6 Jan 2020
    7.8
    High

    CVE-2019-9469

    Last Modified: 21 Nov 2024

    In km_compute_shared_hmac of km4.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-130246677

    Published: 6 Jan 2020
    6.7
    Medium

    CVE-2019-9470

    Last Modified: 21 Nov 2024

    In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-144167528

    Published: 6 Jan 2020
    6.7
    Medium

    CVE-2019-9471

    Last Modified: 21 Nov 2024

    In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-144168326

    Published: 6 Jan 2020
    5.5
    Medium

    CVE-2019-9472

    Last Modified: 21 Nov 2024

    In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-130237611

    Published: 6 Jan 2020
    7.5
    High

    CVE-2020-5840

    Last Modified: 21 Nov 2024

    An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-15602

    Last Modified: 21 Nov 2024

    The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-15603

    Last Modified: 21 Nov 2024

    The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing.

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2016-11017

    Last Modified: 21 Nov 2024

    The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2018-1326

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Jan 2020
    —
    Unknown

    CVE-2018-1300

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2019-20343

    Last Modified: 21 Nov 2024

    The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2020-5519

    Last Modified: 21 Nov 2024

    The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.

    Published: 6 Jan 2020
    7.5
    High

    CVE-2019-15977

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15978

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15979

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15980

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15981

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15982

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    4.9
    Medium

    CVE-2019-15983

    Last Modified: 21 Nov 2024

    A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the DCNM application. The vulnerability exists because the SOAP API improperly handles XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by inserting malicious XML content in an API request. A successful exploit could allow the attacker to read arbitrary files from the affected device. Note: The severity of this vulnerability is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15984

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    7.2
    High

    CVE-2019-15985

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would need administrative privileges on the DCNM application. For more information about these vulnerabilities, see the Details section of this advisory. Note: The severity of these vulnerabilities is aggravated by the vulnerabilities described in the Cisco Data Center Network Manager Authentication Bypass Vulnerabilities advisory, published simultaneously with this one.

    Published: 6 Jan 2020
    6.3
    Medium

    CVE-2019-15999

    Last Modified: 21 Nov 2024

    A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2019-15975

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2019-15976

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jan 2020
    4.3
    Medium

    CVE-2019-20354

    Last Modified: 21 Nov 2024

    The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-5988

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Management Page.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-5989

    Last Modified: 21 Nov 2024

    DOM-based cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote attackers to inject arbitrary web script or HTML via the Analysis Object Page.

    Published: 6 Jan 2020