Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-36314 | LOW | Patched | 3.9 | 2021-04-07 | fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a chec… |
| CVE-2020-36248 | LOW | Patched | 3.9 | 2021-02-19 | The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock fe… |
| CVE-2020-29443 | LOW | 3.9 | 2021-01-26 | ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated. | |
| CVE-2020-7309 | LOW | Patched | 3.9 | 2020-08-26 | Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via spec… |
| CVE-2019-11853 | LOW | Patched | 3.9 | 2020-08-21 | Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4. |
| CVE-2020-13361 | LOW | Patched | 3.9 | 2020-05-28 | In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds ac… |
| CVE-2020-7255 | LOW | 3.9 | 2020-04-15 | Privilege escalation vulnerability in the administrative user interface in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local user… | |
| CVE-2020-11736 | LOW | Patched | 3.9 | 2020-04-13 | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to… |
| CVE-2020-9056 | LOW | Patched | 3.9 | 2020-04-10 | Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the app… |
| CVE-2020-1987 | LOW | Patched | 3.9 | 2020-04-08 | An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information w… |
| CVE-2020-9055 | LOW | 3.9 | 2020-03-30 | Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malici… | |
| CVE-2020-1879 | LOW | 3.9 | 2020-03-20 | There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attac… | |
| CVE-2020-1738 | LOW | Patched | 3.9 | 2020-03-16 | A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user… |
| CVE-2020-1740 | LOW | Patched | 3.9 | 2020-03-16 | A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can re… |
| CVE-2020-1739 | LOW | Patched | 3.9 | 2020-03-12 | A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn comm… |
| CVE-2020-5254 | LOW | Patched | 3.9 | 2020-03-10 | In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue. |
| CVE-2020-5253 | LOW | Patched | 3.9 | 2020-03-10 | NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in… |
| CVE-2020-2731 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerabil… | |
| CVE-2020-2568 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitab… | |
| CVE-2020-2569 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily… | |
| CVE-2019-18994 | LOW | Patched | 3.9 | 2019-12-18 | Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR applica… |
| CVE-2019-2954 | LOW | 3.9 | 2019-10-16 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable … | |
| CVE-2019-2955 | LOW | 3.9 | 2019-10-16 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable … | |
| CVE-2018-20896 | LOW | Patched | 3.9 | 2019-08-01 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). |
| CVE-2019-3591 | LOW | Patched | 3.9 | 2019-07-24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0… |