Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,635 CVEs · Low severity

CVEs (15,635, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 15,635 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2020-36314 LOW Patched 3.9 2021-04-07 fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a chec…
CVE-2020-36248 LOW Patched 3.9 2021-02-19 The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock fe…
CVE-2020-29443 LOW 3.9 2021-01-26 ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
CVE-2020-7309 LOW Patched 3.9 2020-08-26 Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via spec…
CVE-2019-11853 LOW Patched 3.9 2020-08-21 Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
CVE-2020-13361 LOW Patched 3.9 2020-05-28 In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds ac…
CVE-2020-7255 LOW 3.9 2020-04-15 Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local user…
CVE-2020-11736 LOW Patched 3.9 2020-04-13 fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to…
CVE-2020-9056 LOW Patched 3.9 2020-04-10 Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the app…
CVE-2020-1987 LOW Patched 3.9 2020-04-08 An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information w…
CVE-2020-9055 LOW 3.9 2020-03-30 Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malici…
CVE-2020-1879 LOW 3.9 2020-03-20 There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attac…
CVE-2020-1738 LOW Patched 3.9 2020-03-16 A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user…
CVE-2020-1740 LOW Patched 3.9 2020-03-16 A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can re…
CVE-2020-1739 LOW Patched 3.9 2020-03-12 A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn comm…
CVE-2020-5254 LOW Patched 3.9 2020-03-10 In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
CVE-2020-5253 LOW Patched 3.9 2020-03-10 NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in…
CVE-2020-2731 LOW 3.9 2020-01-15 Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerabil…
CVE-2020-2568 LOW 3.9 2020-01-15 Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitab…
CVE-2020-2569 LOW 3.9 2020-01-15 Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily…
CVE-2019-18994 LOW Patched 3.9 2019-12-18 Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR applica…
CVE-2019-2954 LOW 3.9 2019-10-16 Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable …
CVE-2019-2955 LOW 3.9 2019-10-16 Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable …
CVE-2018-20896 LOW Patched 3.9 2019-08-01 cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
CVE-2019-3591 LOW Patched 3.9 2019-07-24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0…