cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2020-5346,https://securityvulnerability.io/vulnerability/CVE-2020-5346,,"RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.",Dell,Rsa Authentication Manager,4.8,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2020-04-15T18:15:00.000Z,0 CVE-2020-5339,https://securityvulnerability.io/vulnerability/CVE-2020-5339,,"RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser.",Dell,Rsa Authentication Manager,4.8,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2020-03-26T13:15:00.000Z,0 CVE-2020-5340,https://securityvulnerability.io/vulnerability/CVE-2020-5340,,"RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser.",Dell,Rsa Authentication Manager,4.8,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2020-03-26T13:15:00.000Z,0 CVE-2019-3768,https://securityvulnerability.io/vulnerability/CVE-2019-3768,,RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to cause information disclosure of local system files by supplying specially crafted XML message.,Dell,Rsa Authentication Manager,6.5,MEDIUM,0.0008999999845400453,false,,false,false,false,,,false,false,,2020-01-03T23:15:00.000Z,0 CVE-2019-18574,https://securityvulnerability.io/vulnerability/CVE-2019-18574,,"RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.",Dell,Rsa Authentication Manager,4.8,MEDIUM,0.000539999979082495,false,,false,false,false,,,false,false,,2019-12-03T21:15:00.000Z,0 CVE-2019-3711,https://securityvulnerability.io/vulnerability/CVE-2019-3711,DSA-2019-038: RSA® Authentication Manager Insecure Credential Management Vulnerability,RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the value of a domain password that another Operations Console administrator had set previously and use it for attacks.,Dell,Rsa Authentication Manager,5.8,MEDIUM,0.000910000002477318,false,,false,false,false,,,false,false,,2019-03-13T21:29:00.000Z,0 CVE-2018-15782,https://securityvulnerability.io/vulnerability/CVE-2018-15782,DSA-2018-226: RSA® Authentication Manager Relative Path Traversal Vulnerability,"The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized access to that system.",Dell,Rsa Authentication Manager,7.7,HIGH,0.0004400000034365803,false,,false,false,false,,,false,false,,2019-01-16T20:29:00.000Z,0 CVE-2018-1247,https://securityvulnerability.io/vulnerability/CVE-2018-1247,,"RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.",Dell,Rsa Authentication Manager Security Console,7.1,HIGH,0.015119999647140503,false,,false,false,false,,,false,false,,2018-05-08T13:29:00.000Z,0 CVE-2018-1248,https://securityvulnerability.io/vulnerability/CVE-2018-1248,,"RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.",Dell,"Rsa Authentication Manager Security Console, Operation Console And Self-service Console",6.1,MEDIUM,0.0010900000343099236,false,,false,false,false,,,false,false,,2018-05-08T13:29:00.000Z,0