Show filters
40,692 Total Results
Displaying 291-300 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Low
CVE-2020-7065
Disclosure Date: March 17, 2020 (last updated November 27, 2024)
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
0
Attacker Value
Very High
CVE-2020-9758
Disclosure Date: March 09, 2020 (last updated November 27, 2024)
An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering this can fetch the username and passwords of the helpdesk employees in the URI. This leads to a privilege escalation, from unauthenticated to user-level access, leading to full account takeover. The attack fetches multiple credentials because they are stored in the database (stored XSS). This affects the mobile/chat URI via the lgn and psswrd parameters.
0
Attacker Value
Very Low
CVE-2020-9371
Disclosure Date: March 04, 2020 (last updated November 27, 2024)
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
0
Attacker Value
Low
CVE-2020-9339
Disclosure Date: February 22, 2020 (last updated November 27, 2024)
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
0
Attacker Value
Very High
CVE-2020-9338
Disclosure Date: February 22, 2020 (last updated November 27, 2024)
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
0
Attacker Value
Very Low
CVE-2020-9266
Disclosure Date: February 18, 2020 (last updated November 27, 2024)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
0
Attacker Value
Low
CVE-2020-7208
Disclosure Date: February 13, 2020 (last updated November 27, 2024)
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
0
Attacker Value
Low
CVE-2020-0655
Disclosure Date: February 11, 2020 (last updated November 27, 2024)
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
0
Attacker Value
Moderate
CVE-2019-17517
Disclosure Date: February 10, 2020 (last updated November 27, 2024)
The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not properly restrict the L2CAP payload length, allowing attackers in radio range to cause a buffer overflow via a crafted Link Layer packet.
0
Attacker Value
Very High
Serpico admin user can be accessed without admin creds
Disclosure Date: January 15, 2020 (last updated November 27, 2024)
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not enhance security. This is problematic in conjunction with XSS.
0