CVE-2012-5474
- EPSS 0.07%
- Published 30.12.2019 20:15:11
- Last modified 21.11.2024 01:44:43
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
CVE-2012-5476
- EPSS 0.15%
- Published 30.12.2019 20:15:11
- Last modified 21.11.2024 01:44:43
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
CVE-2019-20096
- EPSS 0.07%
- Published 30.12.2019 05:15:11
- Last modified 21.11.2024 04:38:03
In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-20041
- EPSS 1.05%
- Published 27.12.2019 08:15:09
- Last modified 21.11.2024 04:37:56
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
CVE-2019-20042
- EPSS 5.05%
- Published 27.12.2019 08:15:09
- Last modified 21.11.2024 04:37:56
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the ...
- EPSS 1.17%
- Published 27.12.2019 08:15:09
- Last modified 21.11.2024 04:37:56
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contri...
CVE-2012-2736
- EPSS 0.08%
- Published 26.12.2019 20:15:11
- Last modified 21.11.2024 01:39:32
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
CVE-2019-16780
- EPSS 3.61%
- Published 26.12.2019 17:15:13
- Last modified 21.11.2024 04:31:10
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of thi...
CVE-2019-16781
- EPSS 3.43%
- Published 26.12.2019 17:15:13
- Last modified 21.11.2024 04:31:10
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading t...
CVE-2019-16789
- EPSS 0.6%
- Published 26.12.2019 17:15:13
- Last modified 21.11.2024 04:31:11
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Spec...