Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16364 1 Zohocorp 1 Manageengine Applications Manager 2020-09-29 9.3 HIGH 8.1 HIGH
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
CVE-2018-6695 1 Mcafee 1 Threat Intelligence Exchange Server 2020-09-29 4.3 MEDIUM 5.9 MEDIUM
SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to spoof servers via acquiring keys from another environment.
CVE-2018-8784 2 Canonical, Freerdp 2 Ubuntu Linux, Freerdp 2020-09-29 7.5 HIGH 9.8 CRITICAL
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.
CVE-2018-8848 1 Philips 1 E-alert Firmware 2020-09-29 5.0 MEDIUM 7.5 HIGH
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.
CVE-2018-8845 1 Advantech 4 Webaccess, Webaccess\/nms, Webaccess Dashboard and 1 more 2020-09-29 7.5 HIGH 9.8 CRITICAL
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to execute arbitrary code.
CVE-2018-8847 1 Eaton 2 9000x, 9000x Firmware 2020-09-29 7.5 HIGH 9.8 CRITICAL
Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.
CVE-2018-8865 1 Lantech 2 Ids 2102, Ids 2102 Firmware 2020-09-29 10.0 HIGH 9.8 CRITICAL
In Lantech IDS 2102 2.0 and prior, a stack-based buffer overflow vulnerability has been identified which may allow remote code execution. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2018-8833 1 Advantech 1 Webaccess Hmi Designer 2020-09-29 6.8 MEDIUM 7.8 HIGH
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
CVE-2018-8834 1 Omron 7 Cx-flnet, Cx-one, Cx-programmer and 4 more 2020-09-29 4.6 MEDIUM 7.8 HIGH
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a heap-based buffer overflow.
CVE-2018-8839 1 Deltaww 1 Pmsoft 2020-09-29 4.6 MEDIUM 7.8 HIGH
Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code execution or cause the application to crash. CVSS v3 base score: 7.1; CVSS vector string: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version.
CVE-2020-3135 1 Cisco 1 Unified Communications Manager 2020-09-29 6.8 MEDIUM 8.8 HIGH
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user.
CVE-2019-1888 1 Cisco 2 Unified Contact Center Express, Unified Ip Interactive Voice Response 2020-09-29 9.0 HIGH 7.2 HIGH
A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials. The vulnerability is due to insufficient restrictions for the content uploaded to an affected system. An attacker could exploit this vulnerability by uploading arbitrary files containing operating system commands that will be executed by an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the web interface and then elevate their privileges to root.
CVE-2019-1003048 1 Jenkins 1 Prqa 2020-09-29 2.1 LOW 7.8 HIGH
A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
CVE-2020-8158 1 Typeorm 1 Typeorm 2020-09-29 7.5 HIGH 9.8 CRITICAL
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
CVE-2020-3137 1 Cisco 1 Email Security Appliance 2020-09-29 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or to access sensitive, browser-based information.
CVE-2020-24624 1 Hpe 1 Utility Computing Service Meter 2020-09-29 5.0 MEDIUM 7.5 HIGH
Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
CVE-2020-24625 1 Hpe 1 Utility Computing Service Meter 2020-09-29 5.0 MEDIUM 7.5 HIGH
Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
CVE-2020-24626 1 Hpe 1 Utility Computing Service Meter 2020-09-29 7.5 HIGH 9.8 CRITICAL
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.
CVE-2017-17589 1 Thumbtack Clone Project 1 Thumbtack Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.
CVE-2017-17643 1 Lynda Clone Project 1 Lynda Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-17586 1 Olx Clone Project 1 Olx Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
CVE-2017-17587 1 Indiamart Clone Project 1 Indiamart Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.
CVE-2017-17588 1 Imdb Clone Project 1 Imdb Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.
CVE-2017-17583 1 Shutterstock Clone Project 1 Shutterstock Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
CVE-2017-17584 1 Makemytrip Clone Project 1 Makemytrip Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2017-17585 1 Monster Clone Project 1 Monster Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
CVE-2017-17579 1 Freelancer Clone Project 1 Freelancer Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
CVE-2017-17580 1 Linkedin Clone Project 1 Linkedin Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.
CVE-2017-17582 1 Grubhub Clone Project 1 Grubhub Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17581 1 Quibids Clone Project 1 Quibids Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
CVE-2017-17577 1 Trademe Clone Project 1 Trademe Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.
CVE-2017-17578 1 Crowdfunding Script Project 1 Crowdfunding Script 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
CVE-2017-17576 1 Gigs Script Project 1 Gigs Script 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or service-provider.php ser parameter.
CVE-2020-25139 1 Observium 1 Observium 2020-09-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via la_id to the /syslog_rules URI for delete_syslog_rule, because of syslog_rules.inc.php.
CVE-2017-17574 1 Care Clone Project 1 Care Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
CVE-2017-17575 1 Groupon Clone Project 1 Groupon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
CVE-2020-25140 1 Observium 1 Observium 2020-09-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur in pages/contacts.inc.php.
CVE-2020-25141 1 Observium 1 Observium 2020-09-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to Cross-Site Scripting (XSS) due to the fact that it is possible to inject and store malicious JavaScript code within it. This can occur via a /device/device=140/tab=wifi/view= URI.
CVE-2020-25142 1 Observium 1 Observium 2020-09-29 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable if any links and forms lack an unpredictable CSRF token. Without such a token, attackers can forge malicious requests, such as for adding Device Settings via the /addsrv URI.
CVE-2017-17571 1 Foodpanda Clone Project 1 Foodpanda Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17572 1 Amazon Clone Project 1 Amazon Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-17570 1 Expedia Clone Project 1 Expedia Clone 2020-09-29 7.5 HIGH 9.8 CRITICAL
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2020-14177 1 Atlassian 1 Jira Server And Data Center 2020-09-29 4.0 MEDIUM 6.5 MEDIUM
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from version 8.6.0 before 8.10.2; and from version 8.11.0 before 8.11.1.
CVE-2020-15189 1 Brassica 1 Soy Cms 2020-09-29 6.5 MEDIUM 7.2 HIGH
SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.
CVE-2020-19447 1 Jdownloads 1 Jdownloads 2020-09-29 5.0 MEDIUM 7.5 HIGH
SQL injection exists in the jdownloads 3.2.63 component for Joomla! com_jdownloads/models/send.php via the f_marked_files_id parameter.
CVE-2020-15930 1 Joplin Project 1 Joplin 2020-09-29 4.3 MEDIUM 6.1 MEDIUM
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
CVE-2020-25788 1 Tt-rss 1 Tiny Tiny Rss 2020-09-29 6.8 MEDIUM 8.1 HIGH
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
CVE-2020-9084 1 Huawei 2 Taurus-an00b, Taurus-an00b Firmware 2020-09-29 4.6 MEDIUM 6.5 MEDIUM
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
CVE-2020-26099 1 Cpanel 1 Cpanel 2020-09-29 5.0 MEDIUM 7.5 HIGH
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
CVE-2020-26098 1 Cpanel 1 Cpanel 2020-09-29 7.5 HIGH 9.8 CRITICAL
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).