Show filters
16,619 Total Results
Displaying 141-150 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2020-11023

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Attacker Value
High

CVE-2020-11100

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Attacker Value
Very Low

CVE-2020-10560

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.
Attacker Value
Very High

CVE-2019-19351

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in Openshift 4 and 3.11.
Attacker Value
Low

CVE-2020-9339

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
Attacker Value
Very High

CVE-2020-9338

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
Attacker Value
Low

CVE-2020-9268

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
Attacker Value
Low

CVE-2020-9269

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
Attacker Value
Very Low

CVE-2020-9266

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
Attacker Value
Moderate

CVE-2019-17519

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.