Sitelet https://web.archive.org/web/20200908095544/https://nvd.nist.gov/

National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database



The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.
 
Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2020-5622 — Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to cause a denial of service which may result in not being able to add newly detected attack source IP addresses as blocking targets... read CVE-2020-5622
    Published: September 02, 2020; 01:15:12 AM -04:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2020-20625 — Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
    Published: August 31, 2020; 12:15:15 PM -04:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2020-17465 — Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.
    Published: August 31, 2020; 12:15:14 PM -04:00

    V3.1: 6.1 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2020-24706 — An issue was discovered in certain WSO2 products. The Try It tool allows Reflected XSS. This affects API Manager through 3.1.0, API Manager Analytics 2.5.0, IS as Key Manager through 5.10.0, Identity Server through 5.10.0, Identity Server Analytics t... read CVE-2020-24706
    Published: August 27, 2020; 12:15:11 PM -04:00

    V3.1: 6.1 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2020-24618 — In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.
    Published: August 27, 2020; 04:15:12 PM -04:00

    V3.1: 6.5 MEDIUM
        V2: 4.0 MEDIUM

  • CVE-2020-3505 — A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device... read CVE-2020-3505
    Published: August 26, 2020; 01:15:14 PM -04:00

    V3.1: 6.5 MEDIUM
        V2: 6.1 MEDIUM

  • CVE-2018-0324 — A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of comma... read CVE-2018-0324
    Published: May 16, 2018; 11:29:00 PM -04:00

    V3.1: 6.7 MEDIUM
        V2: 4.6 MEDIUM

  • CVE-2020-13469 — The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.
    Published: August 31, 2020; 12:15:14 PM -04:00

    V3.1: 4.6 MEDIUM
        V2: 2.1 LOW

  • CVE-2020-7665 — This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.
    Published: September 01, 2020; 10:15:14 AM -04:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2018-0279 — A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vu... read CVE-2018-0279
    Published: May 16, 2018; 11:29:00 PM -04:00

    V3.1: 8.8 HIGH
        V2: 9.0 HIGH

  • CVE-2018-0288 — A vulnerability in Cisco WebEx Recording Format (WRF) Player could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconn... read CVE-2018-0288
    Published: May 02, 2018; 06:29:01 PM -04:00

    V3.1: 5.3 MEDIUM
        V2: 5.0 MEDIUM

  • CVE-2018-0278 — A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin domain protections for the WebSo... read CVE-2018-0278
    Published: May 02, 2018; 06:29:00 PM -04:00

    V3.1: 6.5 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2018-0245 — A vulnerability in the REST API of Cisco 5500 and 8500 Series Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to view system information that under normal circumstances should be prohibited. The vulnerability is... read CVE-2018-0245
    Published: May 02, 2018; 06:29:00 PM -04:00

    V3.1: 5.3 MEDIUM
        V2: 5.0 MEDIUM

  • CVE-2020-7666 — This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.
    Published: September 01, 2020; 10:15:14 AM -04:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2018-0269 — A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly perm... read CVE-2018-0269
    Published: April 19, 2018; 04:29:01 PM -04:00

    V3.1: 4.3 MEDIUM
        V2: 4.3 MEDIUM

  • CVE-2018-0267 — A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient... read CVE-2018-0267
    Published: April 19, 2018; 04:29:01 PM -04:00

    V3.1: 6.5 MEDIUM
        V2: 2.1 LOW

  • CVE-2018-0266 — A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attac... read CVE-2018-0266
    Published: April 19, 2018; 04:29:01 PM -04:00

    V3.1: 4.3 MEDIUM
        V2: 4.0 MEDIUM

  • CVE-2018-0239 — A vulnerability in the egress packet processing functionality of the Cisco StarOS operating system for Cisco Aggregation Services Router (ASR) 5700 Series devices and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remot... read CVE-2018-0239
    Published: April 19, 2018; 04:29:00 PM -04:00

    V3.1: 7.5 HIGH
        V2: 5.0 MEDIUM

  • CVE-2018-0237 — A vulnerability in the file type detection mechanism of the Cisco Advanced Malware Protection (AMP) for Endpoints macOS Connector could allow an unauthenticated, remote attacker to bypass malware detection. The vulnerability occurs because the softwa... read CVE-2018-0237
    Published: April 19, 2018; 04:29:00 PM -04:00

    V3.1: 5.8 MEDIUM
        V2: 5.0 MEDIUM

  • CVE-2018-0228 — A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) conditio... read CVE-2018-0228
    Published: April 19, 2018; 04:29:00 PM -04:00

    V3.1: 8.6 HIGH
        V2: 7.8 HIGH