IDCVSSSažetakZadnje (važnije) ažuriranjeObjavljeno
CVE-2020-15105 5.0
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete au
10-07-2020 - 21:15 10-07-2020 - 21:15
CVE-2020-4042 5.0
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can
10-07-2020 - 20:15 10-07-2020 - 20:15
CVE-2020-11061 5.0
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mi
10-07-2020 - 20:15 10-07-2020 - 20:15
CVE-2020-6114 5.0
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an au
10-07-2020 - 19:38 10-07-2020 - 18:15
CVE-2020-15504 5.0
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build
10-07-2020 - 19:38 10-07-2020 - 17:15
CVE-2020-11081 5.0
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since os
10-07-2020 - 19:38 10-07-2020 - 19:15
CVE-2020-8199 5.0
Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8198 5.0
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8197 5.0
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8196 5.0
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8195 5.0
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure t
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8194 5.0
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8193 5.0
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL en
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8191 5.0
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8190 5.0
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8187 5.0
Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8186 5.0
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-8181 5.0
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
10-07-2020 - 16:39 10-07-2020 - 16:15
CVE-2020-9260 5.0
HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain WI-FI function's default configuration in the system
10-07-2020 - 14:24 10-07-2020 - 14:15
CVE-2020-9258 5.0
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this
10-07-2020 - 14:24 10-07-2020 - 14:15
CVE-2020-7815 5.0
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT__
10-07-2020 - 14:24 10-07-2020 - 14:15
CVE-2020-7814 5.0
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution
10-07-2020 - 14:24 10-07-2020 - 13:15
CVE-2020-3974 5.0
VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful e
10-07-2020 - 14:24 10-07-2020 - 14:15
CVE-2020-5607 5.0
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
10-07-2020 - 02:15 10-07-2020 - 02:15
CVE-2020-4305 5.0
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker c
09-07-2020 - 20:15 09-07-2020 - 19:15
CVE-2020-4173 5.0
IBM Guardium Activity Insights 10.6 and 11.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user
09-07-2020 - 20:15 09-07-2020 - 19:15
CVE-2020-15299 5.0
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the k
09-07-2020 - 19:16 09-07-2020 - 19:15
CVE-2020-15093 5.0
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique sign
09-07-2020 - 19:16 09-07-2020 - 19:15
CVE-2020-15092 5.0
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Goo
09-07-2020 - 19:16 09-07-2020 - 19:15
CVE-2020-15001 5.0
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP con
09-07-2020 - 19:16 09-07-2020 - 19:15
CVE-2020-15526 5.0
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for ale
09-07-2020 - 18:26 09-07-2020 - 17:15
CVE-2020-15000 5.0
A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN. The Reset Code is used to reset the User PIN, but it is disabled by default. A flaw in the implement
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-14171 5.0
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-14170 5.0
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability.
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-13132 5.0
An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key() function in lib/util.c through incorrect error handling code. This could be used to cause a denial of service attack
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-13131 5.0
An issue was discovered in Yubico libykpiv before 2.1.0. lib/util.c in this library (which is included in yubico-piv-tool) does not properly check embedded length fields during device communication. A malicious PIV token can misreport the returned le
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-10756 5.0
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious
09-07-2020 - 18:26 09-07-2020 - 16:15
CVE-2019-17638 5.0
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to
09-07-2020 - 18:26 09-07-2020 - 18:15
CVE-2020-7693 5.0
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-7692 5.0
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authoriza
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-7458 5.0
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arb
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-7457 5.0
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition al
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-5366 5.0
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read acc
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-13994 5.0
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-
09-07-2020 - 15:44 09-07-2020 - 15:15
CVE-2020-13993 5.0
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.
09-07-2020 - 15:44 09-07-2020 - 15:15
CVE-2020-13992 4.3
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a c
09-07-2020 - 15:44 09-07-2020 - 15:15
CVE-2020-12426 5.0
Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
09-07-2020 - 15:44 09-07-2020 - 15:15
CVE-2020-12425 5.0
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
09-07-2020 - 15:44 09-07-2020 - 15:15
CVE-2020-12424 5.0
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects F
09-07-2020 - 15:44 09-07-2020 - 14:15
CVE-2020-12423 5.0
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windo
09-07-2020 - 15:44 09-07-2020 - 15:15
Povratak na vrh stranice Označi odabrano
Povratak na vrh stranice