• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-10953
2020-03-31
N/A
7.5 HIGH
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
CVE-2020-10952
2021-07-21
N/A
6.5 MEDIUM
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
CVE-2020-10951
2020-08-27
N/A
4.7 MEDIUM
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
CVE-2020-10948
2021-07-21
N/A
9.8 CRITICAL
Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.
CVE-2020-10947
Anti-virus For Sophos Home, Sophos
Cyberoamos, Cyberoam, Anti-virus7.6.3, Anti-virus_for_sophos_central, Anti-virus_for_sophos_home, Astaro_security_gateway, Astaro_security_gateway_firmware, Cloud_optix, Cyberoam_cr100ing_utm, Cyberoam_cr100ing_utm_firmware
2021-07-21
N/A
8.8 HIGH
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
CVE-2020-10946
2020-05-28
N/A
6.1 MEDIUM
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.
CVE-2020-10945
2020-08-03
N/A
4.3 MEDIUM
Centreon before 19.10.7 exposes Session IDs in server responses.
CVE-2020-10944
2020-05-06
N/A
5.4 MEDIUM
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
CVE-2020-10942
2022-04-22
N/A
5.3 MEDIUM
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
CVE-2020-10941
2023-02-24
N/A
5.9 MEDIUM
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
« Previous 1 … 4,860 4,861 4,862 4,863 4,864 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE