CVE Notify
19.5K subscribers
4 photos
236K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2020-8787
SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2020-9346
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2020-9347
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20105
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20407
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2020-6646
An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20452
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20453
A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2018-18576
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-11074
A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Full Web Page Sensor and set specific settings when executing the sensor.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20490
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20492
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20493
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20494
In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20495
cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20496
cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20497
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2019-20498
cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

๐ŸŽ–@cveNotify