Vulnerabilities (CVE)
Yack CVE helps teams search and track vulnerabilities.
TOTAL
358,413 CVE
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Webfactoryltd 1Wp Database Reset Jun 17, 2026 Jan 16, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate...Show more |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop. |
2Debian Wireshark2Debian Linux WiresharkJun 17, 2026 Jan 16, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes. |
4Fedoraproject OpensuseOracle+1 more5Fedora LeapSolaris+2 moreJun 17, 2026 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors. |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.examp...Show more |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid ce...Show more |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value. |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jan 21, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeB...Show more |
4Debian Libslirp ProjectOpensuse+1 more4Debian Linux LeapLibslirp+1 moreJun 17, 2026 Jan 16, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead...Show more |
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions of Equinox Conferencin...Show more |
1Avaya 2Aura System Manager WeblmJun 17, 2026 Nov 13, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affe...Show more |
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Of...Show more |
1Avaya 2Aura Communication Manager Aura MessagingJun 17, 2026 Aug 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenti...Show more |
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex...Show more |
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling...Show more |
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, they will be able to view the administrator API credentials. These crede...Show more |
2Elasticsearch Oracle4Communications Billing And Revenue Management Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 moreJun 17, 2026 Jul 27, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform de...Show more |
2Elasticsearch Oracle4Communications Billing And Revenue Management Communications Cloud Native Core Network Function Cloud Native EnvironmentKibana+1 moreJun 17, 2026 Jul 27, 2020 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU...Show more |
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visualization could allow the attacker to obtain sensitive information from, o...Show more |
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation flaw if an attacker is able to create API keys and also authentication to...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary co...Show more |
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kib...Show more |
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web...Show more |
1Elastic 1Elastic Cloud On Kubernetes Jun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able...Show more |
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of...Show more |