Vulnerabilities (CVE)

Filtered by CWE-20
Total 9736 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14671 1 Firefly-iii 1 Firefly Iii 2024-02-28 2.1 LOW 3.3 LOW
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.
CVE-2019-15639 1 Digium 1 Asterisk 2024-02-28 5.0 MEDIUM 7.5 HIGH
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.
CVE-2016-10793 1 Cpanel 1 Cpanel 2024-02-28 6.5 MEDIUM 8.8 HIGH
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
CVE-2018-2015 1 Ibm 1 Api Connect 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.
CVE-2017-18453 1 Cpanel 1 Cpanel 2024-02-28 4.0 MEDIUM 4.9 MEDIUM
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
CVE-2019-5803 2 Google, Opensuse 3 Chrome, Backports, Leap 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2018-14733 1 Odoo 1 Odoo 2024-02-28 5.0 MEDIUM 7.5 HIGH
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
CVE-2018-20813 1 Ivanti 1 Connect Secure 2024-02-28 7.5 HIGH 9.8 CRITICAL
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
CVE-2019-1010234 1 Linuxfoundation 1 Open Network Operating System 2024-02-28 7.5 HIGH 9.8 CRITICAL
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
CVE-2017-18395 1 Cpanel 1 Cpanel 2024-02-28 4.0 MEDIUM 2.7 LOW
cPanel before 68.0.15 does not block a username of ssl (SEC-328).
CVE-2015-9348 1 Codepeople 1 Sell Downloads 2024-02-28 5.0 MEDIUM 7.5 HIGH
The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase IDs.
CVE-2017-18392 1 Cpanel 1 Cpanel 2024-02-28 2.1 LOW 2.0 LOW
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
CVE-2007-6763 1 Sas 1 Sas Drug Development 2024-02-28 6.5 MEDIUM 8.8 HIGH
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
CVE-2019-5799 2 Google, Opensuse 3 Chrome, Backports, Leap 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVE-2019-1306 1 Microsoft 2 Azure Devops Server, Team Foundation Server 2024-02-28 7.5 HIGH 9.8 CRITICAL
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
CVE-2019-7617 1 Elastic 1 Apm Agent 2024-02-28 6.4 MEDIUM 7.2 HIGH
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can control the proxy header. This could result in an attacker redirecting collected APM data to a proxy of their choosing.
CVE-2017-18431 1 Cpanel 1 Cpanel 2024-02-28 5.0 MEDIUM 7.5 HIGH
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
CVE-2018-4440 2 Apple, Microsoft 5 Icloud, Iphone Os, Itunes and 2 more 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.
CVE-2019-1906 1 Cisco 1 Prime Infrastructure 2024-02-28 4.0 MEDIUM 6.5 MEDIUM
A vulnerability in the Virtual Domain system of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to change the virtual domain configuration, which could lead to privilege escalation. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by manipulating requests sent to an affected PI server. A successful exploit could allow the attacker to change the virtual domain configuration and possibly elevate privileges.
CVE-2018-4396 1 Apple 1 Mac Os X 2024-02-28 4.3 MEDIUM 5.5 MEDIUM
A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.