| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Windows Hyper-V Remote Code Execution Vulnerability |
| Windows Error Reporting Information Disclosure Vulnerability |
| Windows Network Connections Service Elevation of Privilege Vulnerability |
| Microsoft SharePoint Elevation of Privilege Vulnerability |
| Azure SDK for C Security Feature Bypass Vulnerability |
| Kerberos Security Feature Bypass Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Windows Backup Engine Elevation of Privilege Vulnerability |
| Azure SDK for Java Security Feature Bypass Vulnerability |
| A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file /crm/crmapi/erp/tabdetail_moduleSave.php. The manipulation of the argument getvaluestring leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 8.6.5.4 can resolve this issue. The affected component should be upgraded. The vendor explains: "All SQL injection vectors were patched via parameterized queries and input sanitization in v8.6.5+." |
| IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior. |
| IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |
| In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests. |
| A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
| IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical error message is returned in a request. This information could be used in further attacks against the system. |