Show filters
281 Total Results
Displaying 131-140 of 281
Sort by:
Attacker Value
Unknown

CVE-2020-2226

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-13484

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
Attacker Value
Unknown

CVE-2020-13483

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
Attacker Value
Unknown

CVE-2020-13758

Disclosure Date: June 01, 2020 (last updated February 21, 2025)
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
Attacker Value
Unknown

CVE-2020-6175

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
Attacker Value
Unknown

CVE-2019-11345

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
Attacker Value
Unknown

CVE-2019-19373

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type. This unserialization can be used to trigger the inclusion of arbitrary files on the filesystem (local file inclusion), and results in remote code execution.
Attacker Value
Unknown

CVE-2019-13629

Disclosure Date: October 03, 2019 (last updated November 27, 2024)
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because crypto/pubkey/ecc_math.c scalar multiplication leaks the bit length of the scalar.
Attacker Value
Unknown

CVE-2019-16106

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
Attacker Value
Unknown

CVE-2019-19374

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during interaction with the File Upload field type, when a custom form exists. (This is related to an information disclosure issue within the File Upload field type that allows users to view the full path to uploaded files, including the product's web root directory.)