Show filters
91 Total Results
Displaying 11-20 of 91
Sort by:
Attacker Value
Unknown

CVE-2020-28597

Disclosure Date: March 03, 2021 (last updated February 22, 2025)
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.
Attacker Value
Unknown

CVE-2020-1461

Disclosure Date: July 14, 2020 (last updated November 28, 2024)
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Attacker Value
Unknown

CVE-2020-1163

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170.
Attacker Value
Unknown

CVE-2020-11883

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
Attacker Value
Unknown

CVE-2020-1002

Disclosure Date: April 15, 2020 (last updated November 27, 2024)
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Attacker Value
Unknown

CVE-2019-15124

Disclosure Date: March 19, 2020 (last updated February 21, 2025)
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
Attacker Value
Unknown

CVE-2019-1255

Disclosure Date: September 23, 2019 (last updated November 27, 2024)
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
Attacker Value
Unknown

CVE-2019-5070

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
Attacker Value
Unknown

CVE-2019-5069

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
Attacker Value
Unknown

CVE-2019-13608

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
0