Latest CVE Feed
-
5.5
MEDIUMCVE-2019-10974
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.... Read more
Affected Products : energyplus- Published: Jul. 26, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20870
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14394
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14409
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10345
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.... Read more
Affected Products : configuration_as_code- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10362
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of e... Read more
Affected Products : configuration_as_code- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14334
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP command.... Read more
Affected Products : 6600-ap_firmware dwl-3600ap_firmware dwl-8610ap_firmware 6600-ap dwl-3600ap dwl-8610ap- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20902
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18398
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18405
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20917
cPanel before 70.0.23 allows any user to disable Solr (SEC-371).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18416
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18464
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).... Read more
Affected Products : cpanel- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-10799
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).... Read more
Affected Products : cpanel- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11551
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.... Read more
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12622
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker cou... Read more
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2136
In Status::readFromParcel of Status.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-15517
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.... Read more
Affected Products : nginx_proxy_manager- Published: Aug. 23, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2103
In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interact... Read more
Affected Products : android- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12755
Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access ... Read more
Affected Products : norton_password_manager- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024