CVE Feed

    Dashboard / CVE

    9.9
    Critical

    CVE-2020-35951

    Last Modified: 21 Nov 2024

    An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It allows users to delete arbitrary files such as wp-config.php file, which could effectively take a site offline and allow an attacker to reinstall with a WordPress instance under their control. This occurred via qsm_remove_file_fd_question, which allowed unauthenticated deletions (even though it was only intended for a person to delete their own quiz-answer files).

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35939

    Last Modified: 21 Nov 2024

    PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35938

    Last Modified: 21 Nov 2024

    PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35937

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to team_import_xml_layouts.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35936

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35935

    Last Modified: 21 Nov 2024

    The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)

    Published: 1 Jan 2021
    4.3
    Medium

    CVE-2020-35934

    Last Modified: 21 Nov 2024

    The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).

    Published: 1 Jan 2021
    6.5
    Medium

    CVE-2020-35933

    Last Modified: 21 Nov 2024

    A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the encoded_options parameter.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2020-35932

    Last Modified: 21 Nov 2024

    Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that might be present with certain other plugins or themes.

    Published: 1 Jan 2021
    4.3
    Medium

    CVE-2021-30155

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.

    Published: 1 Jan 2021
    9.6
    Critical

    CVE-2020-35391

    Last Modified: 21 Nov 2024

    Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.

    Published: 1 Jan 2021
    5.9
    Medium

    CVE-2021-20199

    Last Modified: 21 Nov 2024

    Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.

    Published: 1 Jan 2021
    9.8
    Critical

    CVE-2020-17523

    Last Modified: 21 Nov 2024

    Apache Shiro before 1.7.1, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

    Published: 1 Jan 2021
    7.5
    High

    CVE-2019-25012

    Last Modified: 21 Nov 2024

    The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    8.8
    High

    CVE-2018-25002

    Last Modified: 21 Nov 2024

    uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2017-20001

    Last Modified: 21 Nov 2024

    The AES encryption project 7.x and 8.x for Drupal does not sufficiently prevent attackers from decrypting data, aka SA-CONTRIB-2017-027. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2016-20001

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2016-20002

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2016-20003

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2016-20004

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2016-20005

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2016-20006

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2016-20007

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2016-20008

    Last Modified: 21 Nov 2024

    The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

    Published: 31 Dec 2020
    8.8
    High

    CVE-2020-26165

    Last Modified: 21 Nov 2024

    qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.

    Published: 31 Dec 2020
    7.8
    High

    CVE-2020-35931

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF document via an Evil Annotation Attack because the products fail to consider a null value for a Subtype entry of the Annotation dictionary, in an incremental update.

    Published: 31 Dec 2020
    5.4
    Medium

    CVE-2019-25011

    Last Modified: 21 Nov 2024

    NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demonstrated by /dcim/sites/add/ comments.

    Published: 31 Dec 2020
    5.4
    Medium

    CVE-2020-35930

    Last Modified: 21 Nov 2024

    Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI.

    Published: 31 Dec 2020
    5.5
    Medium

    CVE-2020-11835

    Last Modified: 21 Nov 2024

    In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability.

    Published: 31 Dec 2020
    5.5
    Medium

    CVE-2020-11834

    Last Modified: 21 Nov 2024

    In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability.

    Published: 31 Dec 2020
    5.5
    Medium

    CVE-2020-11833

    Last Modified: 21 Nov 2024

    In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not check the parameter len which causes a vulnerability.

    Published: 31 Dec 2020
    5.5
    Medium

    CVE-2020-11832

    Last Modified: 21 Nov 2024

    In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not checked the parameters, which causes a vulnerability.

    Published: 31 Dec 2020
    5.4
    Medium

    CVE-2020-25799

    Last Modified: 21 Nov 2024

    LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

    Published: 31 Dec 2020
    5.4
    Medium

    CVE-2020-25797

    Last Modified: 21 Nov 2024

    LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.

    Published: 31 Dec 2020
    9.1
    Critical

    CVE-2018-19945

    Last Modified: 21 Nov 2024

    A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target system, if exploited. QNAP have already fixed this vulnerability in the following versions: QTS 4.3.6.0895 build 20190328 (and later) QTS 4.3.4.0899 build 20190322 (and later) This issue does not affect QTS 4.4.x or QTS 4.5.x.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2018-19944

    Last Modified: 21 Nov 2024

    A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)

    Published: 31 Dec 2020
    7.5
    High

    CVE-2018-19941

    Last Modified: 21 Nov 2024

    A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)

    Published: 31 Dec 2020
    6.5
    Medium

    CVE-2018-25001

    Last Modified: 21 Nov 2024

    An issue was discovered in the libpulse-binding crate before 2.5.0 for Rust. proplist::Iterator can cause a use-after-free.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2019-25001

    Last Modified: 21 Nov 2024

    An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumption via nested semantic tags.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2019-25002

    Last Modified: 21 Nov 2024

    An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2019-25003

    Last Modified: 21 Nov 2024

    An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, attackers can obtain sensitive information.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2019-25004

    Last Modified: 21 Nov 2024

    An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, defeating soundness.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2019-25005

    Last Modified: 21 Nov 2024

    An issue was discovered in the chacha20 crate before 0.2.3 for Rust. A ChaCha20 counter overflow makes it easier for attackers to determine plaintext.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2019-25006

    Last Modified: 21 Nov 2024

    An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong answer.

    Published: 31 Dec 2020
    7.5
    High

    CVE-2019-25007

    Last Modified: 21 Nov 2024

    An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can cause a panic.

    Published: 31 Dec 2020
    —
    Unknown

    CVE-2019-25008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-25574. Reason: This candidate is a duplicate of CVE-2020-25574. Notes: All CVE users should reference CVE-2020-25574 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2019-25009

    Last Modified: 21 Nov 2024

    An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2019-25010

    Last Modified: 21 Nov 2024

    An issue was discovered in the failure crate through 2019-11-13 for Rust. Type confusion can occur when __private_get_type_id__ is overridden.

    Published: 31 Dec 2020
    9.8
    Critical

    CVE-2020-35858

    Last Modified: 21 Nov 2024

    An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g., x86) or possibly remote code execution (e.g., ARM).

    Published: 31 Dec 2020
    9.1
    Critical

    CVE-2020-35859

    Last Modified: 21 Nov 2024

    An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs can experience memory corruption.

    Published: 31 Dec 2020