CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2010-3782

    Last Modified: 21 Nov 2024

    obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2014-4553

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in the spreadshirt-rss-3d-cube-flash-gallery plugin 2014 for WordPress allows remote attackers to execute arbitrary web script or HTML via unspecified parameters.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2013-6242

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID because they affect different sets of versions.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2013-7486

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2013-7485

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2013-3621

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3607. Reason: This candidate is a reservation duplicate of CVE-2013-3607. Notes: All CVE users should reference CVE-2013-3607 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Jan 2020
    7.5
    High

    CVE-2013-3620

    Last Modified: 21 Nov 2024

    Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.

    Published: 2 Jan 2020
    8.1
    High

    CVE-2013-3619

    Last Modified: 21 Nov 2024

    Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

    Published: 2 Jan 2020
    5.9
    Medium

    CVE-2014-0161

    Last Modified: 21 Nov 2024

    ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid certificate.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2013-4752

    Last Modified: 21 Nov 2024

    Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

    Published: 2 Jan 2020
    7.5
    High

    CVE-2019-10775

    Last Modified: 21 Nov 2024

    ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

    Published: 2 Jan 2020
    8.8
    High

    CVE-2013-3935

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2013-3936

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.

    Published: 2 Jan 2020
    8.8
    High

    CVE-2019-20219

    Last Modified: 21 Nov 2024

    ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2019-20225

    Last Modified: 21 Nov 2024

    MyBB before 1.8.22 allows an open redirect on login.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2019-20220

    Last Modified: 21 Nov 2024

    In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2019-20221

    Last Modified: 21 Nov 2024

    In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2019-20222

    Last Modified: 21 Nov 2024

    In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.

    Published: 2 Jan 2020
    6.1
    Medium

    CVE-2019-20223

    Last Modified: 21 Nov 2024

    In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.

    Published: 2 Jan 2020
    7.5
    High

    CVE-2019-20213

    Last Modified: 21 Nov 2024

    D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.

    Published: 2 Jan 2020
    9.8
    Critical

    CVE-2019-20330

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

    Published: 2 Jan 2020
    8.8
    High

    CVE-2019-5063

    Last Modified: 21 Nov 2024

    An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions and potential code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

    Published: 2 Jan 2020
    8.8
    High

    CVE-2019-5064

    Last Modified: 21 Nov 2024

    An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.

    Published: 2 Jan 2020
    6.5
    Medium

    CVE-2019-20892

    Last Modified: 21 Nov 2024

    net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

    Published: 2 Jan 2020
    7.5
    High

    CVE-2019-20218

    Last Modified: 21 Nov 2024

    selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.

    Published: 2 Jan 2020
    5.5
    Medium

    CVE-2019-20208

    Last Modified: 11 Jul 2025

    dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.

    Published: 1 Jan 2020
    8.8
    High

    CVE-2019-20205

    Last Modified: 24 Apr 2026

    libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.

    Published: 1 Jan 2020
    5.4
    Medium

    CVE-2019-20204

    Last Modified: 21 Nov 2024

    The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.

    Published: 1 Jan 2020
    5.3
    Medium

    CVE-2019-20203

    Last Modified: 21 Nov 2024

    The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by spoofing the From information of an email message.

    Published: 1 Jan 2020
    7.2
    High

    CVE-2020-5179

    Last Modified: 2 Jan 2026

    Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

    Published: 1 Jan 2020
    6.5
    Medium

    CVE-2015-5595

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).

    Published: 31 Dec 2019
    6.1
    Medium

    CVE-2015-5593

    Last Modified: 21 Nov 2024

    The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></script>", or in an image tag, with the payload as the onerror event.

    Published: 31 Dec 2019
    6.1
    Medium

    CVE-2015-5592

    Last Modified: 21 Nov 2024

    Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.

    Published: 31 Dec 2019
    7.2
    High

    CVE-2015-5591

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-20198

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-20199

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-20200

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-20201

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-20202

    Last Modified: 21 Nov 2024

    An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segmentation fault.

    Published: 31 Dec 2019
    6.1
    Medium

    CVE-2013-7071

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 31 Dec 2019
    9.8
    Critical

    CVE-2013-7070

    Last Modified: 21 Nov 2024

    The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.

    Published: 31 Dec 2019
    9.8
    Critical

    CVE-2004-2776

    Last Modified: 20 Nov 2024

    go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.

    Published: 31 Dec 2019
    8.8
    High

    CVE-2019-18568

    Last Modified: 21 Nov 2024

    Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user.

    Published: 31 Dec 2019
    8.8
    High

    CVE-2019-20197

    Last Modified: 21 Nov 2024

    In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

    Published: 31 Dec 2019
    7.8
    High

    CVE-2013-4161

    Last Modified: 21 Nov 2024

    gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.

    Published: 31 Dec 2019
    9.8
    Critical

    CVE-2019-3984

    Last Modified: 21 Nov 2024

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

    Published: 31 Dec 2019
    6.1
    Medium

    CVE-2019-10227

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.

    Published: 31 Dec 2019
    6.5
    Medium

    CVE-2019-14466

    Last Modified: 21 Nov 2024

    The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.

    Published: 31 Dec 2019
    4.3
    Medium

    CVE-2019-12837

    Last Modified: 21 Nov 2024

    The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.

    Published: 31 Dec 2019
    7.5
    High

    CVE-2019-7751

    Last Modified: 21 Nov 2024

    A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for privilege escalation by dumping the local machine's SAM and SYSTEM database files, and possibly remote code execution.

    Published: 31 Dec 2019