IDCVSSSažetakZadnje (važnije) ažuriranjeObjavljeno
CVE-2020-5217 5.0
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon could be inj
23-01-2020 - 03:21 23-01-2020 - 03:15
CVE-2020-5216 5.0
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injec
23-01-2020 - 03:21 23-01-2020 - 03:15
CVE-2020-7915 5.0
An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator.
23-01-2020 - 02:52 22-01-2020 - 23:15
CVE-2020-5223 5.0
In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HTML leading to a persistent Cross-site scripting (XSS) vulnerability. T
23-01-2020 - 02:52 23-01-2020 - 02:15
CVE-2019-20399 5.0
A timing vulnerability in the Scalar::check_overflow function in Parity libsecp256k1-rs before 0.3.1 potentially allows an attacker to leak information via a side-channel attack.
23-01-2020 - 02:52 23-01-2020 - 00:15
CVE-2019-20398 5.0
A NULL pointer dereference is present in libyang before v1.0-r3 in the function lys_extension_instances_free() due to a copy of unresolved extensions in lys_restr_dup(). Applications that use libyang to parse untrusted input yang files may crash.
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20397 5.0
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20396 5.0
A segmentation fault is present in yyparse in libyang before v1.0-r1 due to a malformed pattern statement value during lys_parse_path parsing.
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20395 5.0
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20394 5.0
A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would caus
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20393 5.0
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20392 5.0
An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrus
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2019-20391 5.0
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used inside a bit. Applications that use libyang to parse untrusted input yang files may crash.
23-01-2020 - 02:52 22-01-2020 - 22:15
CVE-2011-3610 4.3
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
22-01-2020 - 21:27 22-01-2020 - 16:15
CVE-2019-19842 5.0
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.
22-01-2020 - 21:25 22-01-2020 - 21:15
CVE-2019-19841 5.0
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
22-01-2020 - 21:25 22-01-2020 - 21:15
CVE-2019-19840 5.0
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.
22-01-2020 - 21:25 22-01-2020 - 21:15
CVE-2011-3622 5.0
A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.
22-01-2020 - 20:18 22-01-2020 - 20:15
CVE-2020-5221 5.0
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail i
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2019-19843 5.0
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2019-19836 5.0
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2019-19834 5.0
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2019-16792 5.0
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Co
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2016-4761 5.0
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2012-4919 5.0
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
22-01-2020 - 19:26 22-01-2020 - 19:15
CVE-2020-7109 5.0
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
22-01-2020 - 18:26 22-01-2020 - 17:15
CVE-2019-6146 5.0
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
22-01-2020 - 18:26 22-01-2020 - 17:15
CVE-2019-5647 5.0
The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a
22-01-2020 - 18:26 22-01-2020 - 18:15
CVE-2011-3621 5.0
A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.
22-01-2020 - 18:26 22-01-2020 - 18:15
CVE-2011-3614 5.0
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
22-01-2020 - 18:26 22-01-2020 - 18:15
CVE-2011-3613 5.0
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
22-01-2020 - 18:26 22-01-2020 - 18:15
CVE-2011-3612 5.0
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
22-01-2020 - 18:26 22-01-2020 - 18:15
CVE-2011-3611 5.0
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
22-01-2020 - 18:26 22-01-2020 - 17:15
CVE-2011-3595 5.0
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
22-01-2020 - 18:26 22-01-2020 - 16:15
CVE-2020-7228 5.0
The Calculated Fields Form plugin through 1.0.353 for WordPress suffers from multiple Stored XSS vulnerabilities present in the input forms. These can be exploited by an authenticated user.
22-01-2020 - 15:19 22-01-2020 - 15:15
CVE-2020-6960 5.0
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE
22-01-2020 - 15:19 22-01-2020 - 15:15
CVE-2020-6959 5.0
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE
22-01-2020 - 15:19 22-01-2020 - 15:15
CVE-2019-6858 5.0
A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2019-10781 5.0
In schema-inspector before 1.6.9, a maliciously crafted JavaScript object can bypass the `sanitize()` and the `validate()` function used within schema-inspector.
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2019-10780 5.0
BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2018-16272 5.0
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Gal
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2018-16271 5.0
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2018-16270 5.0
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
22-01-2020 - 15:19 22-01-2020 - 14:15
CVE-2011-3582 5.0
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
22-01-2020 - 15:19 22-01-2020 - 15:15
CVE-2019-12490 5.0
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
22-01-2020 - 14:00 22-01-2020 - 06:15
CVE-2018-16269 5.0
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Gala
22-01-2020 - 14:00 22-01-2020 - 13:15
CVE-2018-16268 5.0
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This
22-01-2020 - 14:00 22-01-2020 - 13:15
CVE-2018-16267 5.0
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup wit
22-01-2020 - 14:00 22-01-2020 - 13:15
CVE-2018-16266 5.0
The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy G
22-01-2020 - 14:00 22-01-2020 - 13:15
CVE-2018-16265 5.0
The bt/bt_core system service in Tizen allows an unprivileged process to create a system user interface and control the Bluetooth pairing process, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based
22-01-2020 - 14:00 22-01-2020 - 13:15
Povratak na vrh stranice Označi odabrano
Povratak na vrh stranice