Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (88023 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-15964 | 5 Debian, Fedoraproject, Google and 2 more | 6 Debian Linux, Fedora, Chrome and 3 more | 2024-11-21 | 8.8 High |
| Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||||
| CVE-2020-15960 | 5 Debian, Fedoraproject, Google and 2 more | 6 Debian Linux, Fedora, Chrome and 3 more | 2024-11-21 | 8.8 High |
| Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | ||||
| CVE-2020-15955 | 1 Fehcom | 1 S\/qmail | 2024-11-21 | 5.9 Medium |
| In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker. | ||||
| CVE-2020-15953 | 4 Debian, Fedoraproject, Libetpan Project and 1 more | 4 Debian Linux, Fedora, Libetpan and 1 more | 2024-11-21 | 7.4 High |
| LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a meddler-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection." | ||||
| CVE-2020-15952 | 1 Immuta | 1 Immuta | 2024-11-21 | 9.0 Critical |
| Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS. | ||||
| CVE-2020-15951 | 1 Immuta | 1 Immuta | 2024-11-21 | 6.1 Medium |
| Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials. | ||||
| CVE-2020-15948 | 1 Egain | 1 Chat | 2024-11-21 | 6.1 Medium |
| eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field. | ||||
| CVE-2020-15944 | 1 Gantt-chart Project | 1 Gantt-chart | 2024-11-21 | 5.4 Medium |
| An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated. | ||||
| CVE-2020-15943 | 1 Gantt-chart Project | 1 Gantt-chart | 2024-11-21 | 8.1 High |
| An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated. | ||||
| CVE-2020-15940 | 1 Fortinet | 1 Forticlient Enterprise Management Server | 2024-11-21 | 4.1 Medium |
| An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server. | ||||
| CVE-2020-15937 | 1 Fortinet | 1 Fortios | 2024-11-21 | 4.7 Medium |
| An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard. | ||||
| CVE-2020-15930 | 1 Joplin Project | 1 Joplin | 2024-11-21 | 6.1 Medium |
| An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. | ||||
| CVE-2020-15926 | 1 Rocket.chat | 1 Rocket.chat | 2024-11-21 | 6.1 Medium |
| Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side. | ||||
| CVE-2020-15922 | 1 Midasolutions | 1 Eframework | 2024-11-21 | 9.8 Critical |
| There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required. | ||||
| CVE-2020-15920 | 1 Midasolutions | 1 Eframework | 2024-11-21 | 9.8 Critical |
| There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required. | ||||
| CVE-2020-15919 | 1 Midasolutions | 1 Eframework | 2024-11-21 | 6.1 Medium |
| A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. | ||||
| CVE-2020-15918 | 1 Midasolutions | 1 Eframework | 2024-11-21 | 5.4 Medium |
| Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. | ||||
| CVE-2020-15916 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 9.8 Critical |
| goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter. | ||||
| CVE-2020-15914 | 1 Ea | 1 Origin Client | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window. | ||||
| CVE-2020-15910 | 1 Solarwinds | 1 N-central | 2024-11-21 | 4.7 Medium |
| SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker. | ||||