Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2729 1 Oracle 1 Identity Manager 2020-02-07 5.5 MEDIUM 5.4 MEDIUM
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Identity Manager accessible data as well as unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
CVE-2019-20401 1 Atlassian 1 Jira 2020-02-07 4.3 MEDIUM 6.5 MEDIUM
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
CVE-2020-5528 1 Sixapart 1 Movable Type 2020-02-07 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)) allows remote attackers to inject arbitrary web script or HTML in the block editor and the rich text editor via a specially crafted URL.
CVE-2011-0220 1 Apple 1 Bonjour 2020-02-07 4.9 MEDIUM 5.5 MEDIUM
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
CVE-2019-20173 1 Auth0 1 Login By Auth0 2020-02-07 4.3 MEDIUM 6.1 MEDIUM
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
CVE-2020-8425 1 Cups Easy \(purchase \& Inventory\) Project 1 Cups Easy \(purchase \& Inventory\) 2020-02-07 4.3 MEDIUM 6.5 MEDIUM
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
CVE-2012-6114 1 Git-extras Project 1 Git-extras 2020-02-07 3.6 LOW 5.5 MEDIUM
The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.
CVE-2014-4860 1 Tianocore 1 Edk2 2020-02-07 7.2 HIGH 6.8 MEDIUM
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.
CVE-2020-6854 1 Sos-berlin 1 Jobscheduler 2020-02-07 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from the REST API.
CVE-2020-6855 1 Sos-berlin 1 Jobscheduler 2020-02-07 6.8 MEDIUM 6.5 MEDIUM
A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.
CVE-2019-19539 1 Hp 3 Web Viewpoint T0320, Web Viewpoint T0952, Web Viewpoint T0986 2020-02-07 2.1 LOW 5.5 MEDIUM
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF. By reading ADB or AADB file content within the Installation subvolume, a Guardian user can discover the password of the group.user or alias who acknowledges events from the WVP Events screen.
CVE-2020-6856 1 Sos-berlin 1 Jobscheduler 2020-02-07 4.0 MEDIUM 6.5 MEDIUM
An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.
CVE-2020-7979 1 Gitlab 1 Gitlab 2020-02-07 4.3 MEDIUM 5.3 MEDIUM
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
CVE-2020-5218 1 Sylius 1 Sylius 2020-02-07 4.0 MEDIUM 4.3 MEDIUM
Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if no sylius_channel.debug is set explicitly in the configuration, the default value which is kernel.debug will be not resolved and cast to boolean, enabling this debug feature even if that parameter is set to false. Patch has been provided for Sylius 1.3.x and newer - 1.3.16, 1.4.12, 1.5.9, 1.6.5. Versions older than 1.3 are not covered by our security support anymore.
CVE-2013-2682 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2020-02-07 4.3 MEDIUM 4.3 MEDIUM
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
CVE-2013-2683 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2020-02-07 5.0 MEDIUM 5.3 MEDIUM
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.
CVE-2013-2684 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2020-02-07 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2020-7971 1 Gitlab 1 Gitlab 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
GitLab EE 11.0 and later through 12.7.2 allows XSS.
CVE-2020-8421 1 Joomla 1 Joomla\! 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
CVE-2011-1150 1 Bbpress 1 Bbpress 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
bbPress through 1.0.2 has XSS in /bb-login.php url via the re parameter.
CVE-2020-7210 1 Umbraco 1 Umbraco Cms 2020-02-06 4.3 MEDIUM 4.3 MEDIUM
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2020-8120 1 Nextcloud 1 Nextcloud 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
CVE-2020-5236 1 Agendaless 1 Waitress 2020-02-06 6.8 MEDIUM 6.5 MEDIUM
Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like "Bad-header: xxxxxxxxxxxxxxx\x10" is received, it will cause the regular expression engine to catastrophically backtrack causing the process to use 100% CPU time and blocking any other interactions. This allows an attacker to send a single request with an invalid header and take the service offline. This issue was introduced in version 1.4.2 when the regular expression was updated to attempt to match the behaviour required by errata associated with RFC7230. The regular expression that is used to validate incoming headers has been updated in version 1.4.3, it is recommended that people upgrade to the new version of Waitress as soon as possible.
CVE-2020-8123 1 Strapi 1 Strapi 2020-02-06 4.0 MEDIUM 4.9 MEDIUM
A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.
CVE-2019-4732 2 Ibm, Microsoft 3 Sdk, Websphere Application Server, Windows 2020-02-06 6.9 MEDIUM 6.5 MEDIUM
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.
CVE-2020-7967 1 Gitlab 1 Gitlab 2020-02-06 4.0 MEDIUM 4.3 MEDIUM
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
CVE-2019-15618 1 Nextcloud 1 Nextcloud Server 2020-02-06 3.5 LOW 4.8 MEDIUM
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
CVE-2019-4674 1 Ibm 1 Security Identity Manager 2020-02-06 4.0 MEDIUM 4.9 MEDIUM
IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 171510.
CVE-2020-8117 1 Nextcloud 1 Nextcloud Server 2020-02-06 4.0 MEDIUM 4.3 MEDIUM
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
CVE-2019-4451 1 Ibm 1 Security Identity Manager 2020-02-06 3.5 LOW 5.4 MEDIUM
IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163493.
CVE-2020-7973 1 Gitlab 1 Gitlab 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
GitLab through 12.7.2 allows XSS.
CVE-2019-11251 1 Kubernetes 1 Kubernetes 2020-02-06 4.3 MEDIUM 5.7 MEDIUM
The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.
CVE-2020-7977 1 Gitlab 1 Gitlab 2020-02-06 4.3 MEDIUM 5.3 MEDIUM
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
CVE-2019-10073 1 Apache 1 Ofbiz 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616
CVE-2020-8548 1 Masscode 1 Masscode 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).
CVE-2014-4859 1 Tianocore 1 Edk2 2020-02-06 7.2 HIGH 6.8 MEDIUM
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.
CVE-2014-3230 1 Lwp\ 1 \ 2020-02-06 4.3 MEDIUM 5.9 MEDIUM
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.
CVE-2013-4187 1 Flippy Project 1 Flippy 2020-02-06 4.0 MEDIUM 6.5 MEDIUM
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.
CVE-2014-8338 1 Videowhisper 1 Webcam 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary web script or HTML via a URL to a crafted SVG file in the feed parameter.
CVE-2018-13122 1 Onefilecms 1 Onefilecms 2020-02-06 5.5 MEDIUM 6.5 MEDIUM
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.
CVE-2018-7475 1 Icewarp 1 Mail Server 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
CVE-2011-1009 1 Vanillaforums 1 Vanilla 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
CVE-2011-1069 1 Phpshop 1 Phpshop 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
PHPShop through 0.8.1 has XSS.
CVE-2010-4662 1 Pmwiki 1 Pmwiki 2020-02-06 4.3 MEDIUM 6.1 MEDIUM
PmWiki before 2.2.21 has XSS.
CVE-2014-8328 1 Dynamic Content Elements Project 1 Dynamic Content Elements 2020-02-05 5.0 MEDIUM 5.3 MEDIUM
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
CVE-2013-2631 1 Tinywebgallery 1 Tinywebgallery 2020-02-05 5.0 MEDIUM 5.3 MEDIUM
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
CVE-2015-3612 1 Fortinet 1 Fortimanager 2020-02-05 3.5 LOW 5.4 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiWeb auto update service page.
CVE-2020-8496 1 Kronos 1 Web Time And Attendance 2020-02-05 3.5 LOW 4.8 MEDIUM
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
CVE-2020-8493 1 Kronos 1 Web Time And Attendance 2020-02-05 3.5 LOW 4.8 MEDIUM
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.
CVE-2013-2673 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2020-02-05 4.6 MEDIUM 6.8 MEDIUM
Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized access.