Search

Search Results (354816 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-15526 1 Red-gate 1 Sql Monitor 2024-11-21 5.9 Medium
In Redgate SQL Monitor 7.1.4 through 10.1.6 (inclusive), the scope for disabling some TLS security certificate checks can extend beyond that defined by various options on the Configuration > Notifications pages to disable certificate checking for alert notifications. These TLS security checks are also ignored during monitoring of VMware machines. This would make SQL Monitor vulnerable to potential man-in-the-middle attacks when sending alert notification emails, posting to Slack or posting to webhooks. The vulnerability is fixed in version 10.1.7.
CVE-2020-15525 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
GitLab EE 11.3 through 13.1.2 has Incorrect Access Control because of the Maven package upload endpoint.
CVE-2020-15523 3 Microsoft, Netapp, Python 3 Windows, Snapcenter, Python 2024-11-21 7.8 High
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.
CVE-2020-15521 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 6.1 Medium
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
CVE-2020-15518 1 Veeam 2 Veeam Availability Suite, Veeam Backup \& Replication 2024-11-21 8.8 High
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
CVE-2020-15517 1 Faceted Search Project 1 Faceted Search 2024-11-21 5.4 Medium
The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.
CVE-2020-15516 1 Mm Forum Project 1 Mm Forum 2024-11-21 5.4 Medium
The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
CVE-2020-15515 1 Turn\! Project 1 Turn\! 2024-11-21 8.8 High
The turn extension through 0.3.2 for TYPO3 allows Remote Code Execution.
CVE-2020-15514 1 Jh Captcha Project 1 Jh Captcha 2024-11-21 5.4 Medium
The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.
CVE-2020-15513 1 Mittwald 1 Typo3 Forum 2024-11-21 5.3 Medium
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
CVE-2020-15511 1 Hashicorp 1 Terraform Enterprise 2024-11-21 5.3 Medium
HashiCorp Terraform Enterprise up to v202006-1 contained a default signup page that allowed user registration even when disabled, bypassing SAML enforcement. Fixed in v202007-1.
CVE-2020-15509 1 Nordicsemi 2 Android Ble Library, Dfu Library 2024-11-21 6.5 Medium
Nordic Semiconductor Android BLE Library through 2.2.1 and DFU Library through 1.10.4 for Android (as used by nRF Connect and other applications) can engage in unencrypted communication while showing the user that the communication is purportedly encrypted. The problem is in bond creation (e.g., internalCreateBond in BleManagerHandler).
CVE-2020-15507 1 Mobileiron 5 Cloud, Core, Enterprise Connector and 2 more 2024-11-21 7.5 High
An arbitrary file reading vulnerability in MobileIron Core versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to read files on the system via unspecified vectors.
CVE-2020-15506 1 Mobileiron 5 Cloud, Core, Enterprise Connector and 2 more 2024-11-21 9.8 Critical
An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors.
CVE-2020-15504 1 Sophos 1 Xg Firewall Firmware 2024-11-21 9.8 Critical
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.
CVE-2020-15503 4 Debian, Fedoraproject, Libraw and 1 more 4 Debian Linux, Fedora, Libraw and 1 more 2024-11-21 7.5 High
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
CVE-2020-15502 1 Duckduckgo 1 Duckduckgo 2024-11-21 7.5 High
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
CVE-2020-15501 1 Smarter 1 Smarter Coffee Maker 1st Generation 2024-11-21 6.5 Medium
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2020-15500 1 Tileserver 1 Tileservergl 2024-11-21 6.1 Medium
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application's main page, causing reflected XSS.
CVE-2020-15499 1 Asus 2 Rt-ac1900p, Rt-ac1900p Firmware 2024-11-21 6.1 Medium
An issue was discovered on ASUS RT-AC1900P routers before 3.0.0.4.385_20253. They allow XSS via spoofed Release Notes on the Firmware Upgrade page.