CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-5990

    Last Modified: 21 Nov 2024

    Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.

    Published: 6 Jan 2020
    8.8
    High

    CVE-2019-5987

    Last Modified: 21 Nov 2024

    Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

    Published: 6 Jan 2020
    7.1
    High

    CVE-2019-20352

    Last Modified: 21 Nov 2024

    In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2020-5191

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.

    Published: 6 Jan 2020
    8.8
    High

    CVE-2020-5192

    Last Modified: 21 Nov 2024

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-19265

    Last Modified: 21 Nov 2024

    IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.

    Published: 6 Jan 2020
    5.4
    Medium

    CVE-2019-19266

    Last Modified: 21 Nov 2024

    IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.

    Published: 6 Jan 2020
    3.3
    Low

    CVE-2019-15601

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Jan 2020
    5.5
    Medium

    CVE-2020-21685

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

    Published: 6 Jan 2020
    4.3
    Medium

    CVE-2019-18179

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.

    Published: 6 Jan 2020
    5.5
    Medium

    CVE-2020-21686

    Last Modified: 21 Nov 2024

    A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.

    Published: 6 Jan 2020
    5.5
    Medium

    CVE-2020-21687

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

    Published: 6 Jan 2020
    4.8
    Medium

    CVE-2020-5306

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.

    Published: 5 Jan 2020
    4.8
    Medium

    CVE-2020-5305

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.

    Published: 5 Jan 2020
    8.8
    High

    CVE-2019-20155

    Last Modified: 21 Nov 2024

    An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server.

    Published: 5 Jan 2020
    6.1
    Medium

    CVE-2019-20154

    Last Modified: 21 Nov 2024

    An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters allows remote attackers to inject arbitrary web script or HTML.

    Published: 5 Jan 2020
    4.9
    Medium

    CVE-2019-20153

    Last Modified: 21 Nov 2024

    An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files (including configuration files containing administrative credentials).

    Published: 5 Jan 2020
    4.3
    Medium

    CVE-2019-20077

    Last Modified: 21 Nov 2024

    The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.

    Published: 5 Jan 2020
    8.8
    High

    CVE-2019-20004

    Last Modified: 21 Nov 2024

    An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.

    Published: 5 Jan 2020
    7.5
    High

    CVE-2019-19629

    Last Modified: 21 Nov 2024

    In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private code would be disclosed via the Group Search API provided by the Elasticsearch integration.

    Published: 5 Jan 2020
    9.8
    Critical

    CVE-2019-19628

    Last Modified: 21 Nov 2024

    In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

    Published: 5 Jan 2020
    7.5
    High

    CVE-2019-19314

    Last Modified: 21 Nov 2024

    GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.

    Published: 5 Jan 2020
    7.5
    High

    CVE-2019-19313

    Last Modified: 21 Nov 2024

    GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible to create, edit, or view issues and commits.

    Published: 5 Jan 2020
    5.8
    Medium

    CVE-2019-19312

    Last Modified: 21 Nov 2024

    GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.

    Published: 5 Jan 2020
    6.1
    Medium

    CVE-2019-20336

    Last Modified: 21 Nov 2024

    In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.

    Published: 5 Jan 2020
    7.2
    High

    CVE-2019-20337

    Last Modified: 21 Nov 2024

    In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.

    Published: 5 Jan 2020
    6.1
    Medium

    CVE-2015-9540

    Last Modified: 21 Nov 2024

    Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

    Published: 4 Jan 2020
    9.8
    Critical

    CVE-2020-5499

    Last Modified: 21 Nov 2024

    Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

    Published: 4 Jan 2020
    6.1
    Medium

    CVE-2020-5497

    Last Modified: 21 Nov 2024

    The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript.

    Published: 4 Jan 2020
    5.5
    Medium

    CVE-2019-20334

    Last Modified: 21 Nov 2024

    In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.

    Published: 4 Jan 2020
    6.8
    Medium

    CVE-2019-20792

    Last Modified: 21 Nov 2024

    OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.

    Published: 4 Jan 2020
    6.5
    Medium

    CVE-2019-5845

    Last Modified: 21 Nov 2024

    Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-5846

    Last Modified: 21 Nov 2024

    Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-13766

    Last Modified: 21 Nov 2024

    Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-5844

    Last Modified: 21 Nov 2024

    Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-13765

    Last Modified: 21 Nov 2024

    Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-3768

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9542

    Last Modified: 21 Nov 2024

    : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9541

    Last Modified: 21 Nov 2024

    : Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9539

    Last Modified: 21 Nov 2024

    : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9540

    Last Modified: 21 Nov 2024

    : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9537

    Last Modified: 21 Nov 2024

    : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2019-9538

    Last Modified: 21 Nov 2024

    : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL parameter of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2014-8516

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2014-8337

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2014-5516

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request.

    Published: 3 Jan 2020
    8.8
    High

    CVE-2014-5140

    Last Modified: 21 Nov 2024

    The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2014-10398

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2014-4196

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attackers to inject arbitrary web script or HTML via the colorstyle parameter.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2012-5878

    Last Modified: 21 Nov 2024

    Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.

    Published: 3 Jan 2020