Search
15,095 CVEs · Low severity
CVEs (15,095, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 15,095 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11736 | LOW | Patched | 3.9 | 2020-04-13 | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to… |
| CVE-2020-9056 | LOW | Patched | 3.9 | 2020-04-10 | Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the app… |
| CVE-2020-1987 | LOW | Patched | 3.9 | 2020-04-08 | An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information w… |
| CVE-2020-9055 | LOW | 3.9 | 2020-03-30 | Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malici… | |
| CVE-2020-1879 | LOW | 3.9 | 2020-03-20 | There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attac… | |
| CVE-2020-1738 | LOW | Patched | 3.9 | 2020-03-16 | A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user… |
| CVE-2020-1740 | LOW | Patched | 3.9 | 2020-03-16 | A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can re… |
| CVE-2020-1739 | LOW | Patched | 3.9 | 2020-03-12 | A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn comm… |
| CVE-2020-5254 | LOW | Patched | 3.9 | 2020-03-10 | In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue. |
| CVE-2020-5253 | LOW | Patched | 3.9 | 2020-03-10 | NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in… |
| CVE-2020-2731 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerabil… | |
| CVE-2020-2568 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitab… | |
| CVE-2020-2569 | LOW | 3.9 | 2020-01-15 | Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily… | |
| CVE-2019-18994 | LOW | Patched | 3.9 | 2019-12-18 | Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR applica… |
| CVE-2019-2954 | LOW | 3.9 | 2019-10-16 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable … | |
| CVE-2019-2955 | LOW | 3.9 | 2019-10-16 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable … | |
| CVE-2018-20896 | LOW | Patched | 3.9 | 2019-08-01 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). |
| CVE-2019-3591 | LOW | Patched | 3.9 | 2019-07-24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0… |
| CVE-2019-2807 | LOW | 3.9 | 2019-07-23 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zones). The supported version that is affected is 11.4. Easily exploitable… | |
| CVE-2019-9700 | LOW | Patched | 3.9 | 2019-07-16 | Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address … |
| CVE-2019-5296 | LOW | Patched | 3.9 | 2019-06-04 | Mate20 Huawei smartphones versions earlier than HMA-AL00C00B175 have an out-of-bounds read vulnerability. An attacker with a high permission runs some specific commands on … |
| CVE-2015-1327 | LOW | 3.9 | 2019-04-22 | Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to … | |
| CVE-2019-0127 | LOW | 3.9 | 2019-02-18 | Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access. | |
| CVE-2018-3266 | LOW | 3.9 | 2018-10-17 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Verified Boot). The supported version that is affected is 11.3. Difficult to expl… | |
| CVE-2018-7947 | LOW | Patched | 3.9 | 2018-07-31 | Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a m… |