IDCVSSSažetakZadnje (važnije) ažuriranjeObjavljeno
CVE-2020-11548 5.0
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
05-04-2020 - 00:15 05-04-2020 - 00:15
CVE-2020-11547 5.0
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by typ
05-04-2020 - 00:15 05-04-2020 - 00:15
CVE-2020-11542 5.0
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.
04-04-2020 - 22:15 04-04-2020 - 22:15
CVE-2020-11533 5.0
Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).
04-04-2020 - 20:15 04-04-2020 - 20:15
CVE-2020-11529 5.0
Common/Grav.php in Grav before 1.6.23 has an Open Redirect.
04-04-2020 - 19:15 04-04-2020 - 19:15
CVE-2020-11528 5.0
bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.
04-04-2020 - 17:15 04-04-2020 - 17:15
CVE-2020-11527 5.0
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
04-04-2020 - 17:15 04-04-2020 - 17:15
CVE-2020-11518 5.0
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
04-04-2020 - 14:15 04-04-2020 - 14:15
CVE-2020-5348 5.0
Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to
04-04-2020 - 00:15 04-04-2020 - 00:15
CVE-2020-5347 5.0
Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
04-04-2020 - 00:15 04-04-2020 - 00:15
CVE-2020-8147 5.0
Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.
03-04-2020 - 22:51 03-04-2020 - 21:15
CVE-2020-8143 5.0
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.T
03-04-2020 - 22:51 03-04-2020 - 21:15
CVE-2020-8142 5.0
A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change
03-04-2020 - 22:51 03-04-2020 - 21:15
CVE-2020-8639 5.0
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (c
03-04-2020 - 19:20 03-04-2020 - 19:15
CVE-2020-8638 5.0
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
03-04-2020 - 19:20 03-04-2020 - 19:15
CVE-2020-8637 5.0
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
03-04-2020 - 19:20 03-04-2020 - 19:15
CVE-2020-6994 5.0
A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP re
03-04-2020 - 19:20 03-04-2020 - 19:15
CVE-2020-7008 5.0
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
03-04-2020 - 18:22 03-04-2020 - 18:15
CVE-2020-7004 5.0
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application
03-04-2020 - 18:22 03-04-2020 - 18:15
CVE-2020-7000 5.0
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exp
03-04-2020 - 18:22 03-04-2020 - 18:15
CVE-2020-10601 5.0
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniques, or ove
03-04-2020 - 18:22 03-04-2020 - 18:15
CVE-2020-10599 5.0
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.
03-04-2020 - 18:22 03-04-2020 - 18:15
CVE-2020-10960 5.0
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquer
03-04-2020 - 16:17 03-04-2020 - 15:15
CVE-2020-10689 5.0
A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful ex
03-04-2020 - 16:17 03-04-2020 - 15:15
CVE-2019-17231 5.0
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
03-04-2020 - 16:17 03-04-2020 - 15:15
CVE-2019-17230 5.0
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
03-04-2020 - 16:17 03-04-2020 - 15:15
CVE-2020-4273 5.0
IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input. IBM X-Force ID: 175977.
03-04-2020 - 13:38 03-04-2020 - 13:15
CVE-2020-11501 5.0
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes
03-04-2020 - 13:38 03-04-2020 - 13:15
CVE-2020-11500 5.0
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
03-04-2020 - 13:38 03-04-2020 - 13:15
CVE-2019-18905 5.0
A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used t
03-04-2020 - 12:58 03-04-2020 - 11:15
CVE-2019-18904 5.0
A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterpri
03-04-2020 - 12:58 03-04-2020 - 07:15
CVE-2018-17954 5.0
A Least Privilege Violation vulnerability in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause beco
03-04-2020 - 12:58 03-04-2020 - 07:15
CVE-2020-5283 5.0
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise truste
03-04-2020 - 01:15 03-04-2020 - 00:15
CVE-2020-11499 5.0
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.
02-04-2020 - 23:15 02-04-2020 - 23:15
CVE-2020-11498 5.0
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the u
02-04-2020 - 23:15 02-04-2020 - 23:15
CVE-2020-7630 7.5
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7629 7.5
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7628 7.5
install-package through 1.1.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the device function.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7627 7.5
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7626 7.5
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7625 7.5
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-7624 7.5
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-10515 5.0
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.
02-04-2020 - 22:15 02-04-2020 - 22:15
CVE-2020-9067 5.2
There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to perform remote code execution on the affected products when the affected product functions as an optical line terminal (OLT). Affec
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-7623 5.0
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-7621 5.0
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-7620 5.0
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-7619 5.0
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-11494 5.0
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration la
02-04-2020 - 21:15 02-04-2020 - 21:15
CVE-2020-4303 4.3
IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading
02-04-2020 - 21:00 02-04-2020 - 15:15
Povratak na vrh stranice Označi odabrano
Povratak na vrh stranice