Total
9736 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-18574 | 1 Ninjaforms | 1 Ninja Forms | 2024-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder. | |||||
CVE-2018-10947 | 1 Polycom | 2 Realpresence Debut, Realpresence Debut Firmware | 2024-02-28 | 2.9 LOW | 3.1 LOW |
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted. | |||||
CVE-2018-20580 | 1 Smartbear | 1 Readyapi | 2024-02-28 | 9.3 HIGH | 8.8 HIGH |
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | |||||
CVE-2019-11595 | 1 Ublockorigin | 1 Ublock Origin | 2024-02-28 | 6.8 MEDIUM | 9.0 CRITICAL |
In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect. | |||||
CVE-2016-10775 | 1 Cpanel | 1 Cpanel | 2024-02-28 | 6.8 MEDIUM | 6.5 MEDIUM |
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173). | |||||
CVE-2019-11980 | 1 Hp | 1 Intelligent Management Center | 2024-02-28 | 9.0 HIGH | 8.8 HIGH |
A remote code exection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. | |||||
CVE-2019-11340 | 1 Matrix | 1 Sydent | 2024-02-28 | 4.3 MEDIUM | 5.9 MEDIUM |
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring. | |||||
CVE-2018-4368 | 1 Apple | 4 Iphone Os, Mac Os X, Tvos and 1 more | 2024-02-28 | 4.0 MEDIUM | 6.5 MEDIUM |
A denial of service issue was addressed with improved validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, watchOS 5.1. | |||||
CVE-2017-12652 | 2 Libpng, Netapp | 2 Libpng, Active Iq Unified Manager | 2024-02-28 | 7.5 HIGH | 9.8 CRITICAL |
libpng before 1.6.32 does not properly check the length of chunks against the user limit. | |||||
CVE-2017-18439 | 1 Cpanel | 1 Cpanel | 2024-02-28 | 6.5 MEDIUM | 6.3 MEDIUM |
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243). | |||||
CVE-2018-20846 | 1 Uclouvain | 1 Openjpeg | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
Out-of-bounds accesses in the functions pi_next_lrcp, pi_next_rlcp, pi_next_rpcl, pi_next_pcrl, pi_next_rpcl, and pi_next_cprl in openmj2/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash). | |||||
CVE-2018-20106 | 1 Opensuse | 1 Yast2-printer | 2024-02-28 | 9.3 HIGH | 8.1 HIGH |
In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast. | |||||
CVE-2017-5211 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. | |||||
CVE-2019-5801 | 3 Apple, Google, Opensuse | 4 Iphone Os, Chrome, Backports and 1 more | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |||||
CVE-2019-5597 | 1 Freebsd | 1 Freebsd | 2024-02-28 | 6.4 MEDIUM | 9.1 CRITICAL |
In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter. | |||||
CVE-2019-12816 | 1 Znc | 1 Znc | 2024-02-28 | 6.5 MEDIUM | 8.8 HIGH |
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name. | |||||
CVE-2018-15734 | 1 Stopzilla | 1 Antimalware | 2024-02-28 | 2.1 LOW | 5.5 MEDIUM |
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000206B. | |||||
CVE-2019-1800 | 1 Cisco | 2 Wireless Lan Controller, Wireless Lan Controller Software | 2024-02-28 | 6.1 MEDIUM | 6.5 MEDIUM |
A vulnerability in the handling of Inter-Access Point Protocol (IAPP) messages by Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability exist because the software improperly validates input on fields within IAPP messages. An attacker could exploit the vulnerability by sending malicious IAPP messages to an affected device. A successful exploit could allow the attacker to cause the Cisco WLC Software to reload, resulting in a DoS condition. Software versions prior to 8.2.170.0, 8.5.150.0, and 8.8.100.0 are affected. | |||||
CVE-2019-1079 | 1 Microsoft | 1 Visual Studio | 2024-02-28 | 4.3 MEDIUM | 6.5 MEDIUM |
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'. | |||||
CVE-2019-15640 | 1 Limesurvey | 1 Limesurvey | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image. |