Show filters
570 Total Results
Displaying 291-300 of 570
Sort by:
Attacker Value
Unknown
CVE-2020-7475
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2012-1903
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
XSS in Telligent Community 5.6.583.20496 via a flash file and related to the allowScriptAccess parameter.
0
Attacker Value
Unknown
CVE-2020-2115
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2020-5529
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper way, hence a malicious JavaScript code can execute arbitrary Java code on the application.
0
Attacker Value
Unknown
CVE-2020-3129
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted data to a specific field within the interface. A successful exploit could allow the attacker to store an XSS attack within the interface. This stored XSS attack would then be executed on the system of any user viewing the attacker-supplied data element.
0
Attacker Value
Unknown
CVE-2020-3130
Disclosure Date: January 22, 2020 (last updated February 22, 2025)
A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web management interface. A successful exploit could allow the attacker to overwrite files on the underlying filesystem of an affected system. Valid administrator credentials are required to access the system.
0
Attacker Value
Unknown
CVE-2020-5319
Disclosure Date: January 20, 2020 (last updated February 21, 2025)
Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of Service (Storage Processor Panic) by sending an out of order SSH protocol sequence.
0
Attacker Value
Unknown
CVE-2019-6855
Disclosure Date: January 06, 2020 (last updated February 21, 2025)
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
0
Attacker Value
Unknown
CVE-2019-9197
Disclosure Date: December 31, 2019 (last updated November 27, 2024)
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
0