CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2019-11862

    Last Modified: 21 Nov 2024

    The SSH service on ALEOS before 4.12.0, 4.9.5, 4.4.9 allows traffic proxying.

    Published: 21 Aug 2020
    5.7
    Medium

    CVE-2019-11858

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities exist in the AceManager Web API of ALEOS before 4.13.0, 4.9.5, and 4.4.9.

    Published: 21 Aug 2020
    3.9
    Low

    CVE-2019-11853

    Last Modified: 21 Nov 2024

    Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.

    Published: 21 Aug 2020
    6
    Medium

    CVE-2019-11859

    Last Modified: 21 Nov 2024

    A buffer overflow exists in the SMS handler API of ALEOS before 4.13.0, 4.9.5, 4.9.4 that may allow code execution as root.

    Published: 21 Aug 2020
    9.1
    Critical

    CVE-2019-11857

    Last Modified: 21 Nov 2024

    Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

    Published: 21 Aug 2020
    3.3
    Low

    CVE-2019-11856

    Last Modified: 21 Nov 2024

    A nonce reuse vulnerability exists in the ACEView service of ALEOS before 4.13.0, 4.9.5, and 4.4.9 allowing message replay. Captured traffic to the ACEView service can be replayed to other gateways sharing the same credentials.

    Published: 21 Aug 2020
    8.1
    High

    CVE-2019-11855

    Last Modified: 21 Nov 2024

    An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

    Published: 21 Aug 2020
    3.7
    Low

    CVE-2019-11852

    Last Modified: 21 Nov 2024

    An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive information may be disclosed via the ACEviewservice, accessible by default on the LAN.

    Published: 21 Aug 2020
    4.1
    Medium

    CVE-2019-11848

    Last Modified: 21 Nov 2024

    An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.

    Published: 21 Aug 2020
    6.3
    Medium

    CVE-2019-11850

    Last Modified: 21 Nov 2024

    A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

    Published: 21 Aug 2020
    6.3
    Medium

    CVE-2019-11849

    Last Modified: 21 Nov 2024

    A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code execution.

    Published: 21 Aug 2020
    7.3
    High

    CVE-2019-11847

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the command shell.

    Published: 21 Aug 2020
    6.5
    Medium

    CVE-2020-14201

    Last Modified: 21 Nov 2024

    Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

    Published: 21 Aug 2020
    5.4
    Medium

    CVE-2020-3975

    Last Modified: 21 Nov 2024

    VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with access to create and edit applications or create storage groups, may be able to inject malicious script which will be executed by a victim's browser when viewing.

    Published: 21 Aug 2020
    5.8
    Medium

    CVE-2020-5775

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.

    Published: 21 Aug 2020
    8.5
    High

    CVE-2020-15147

    Last Modified: 21 Nov 2024

    Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users with specifically crafted "going live" messages to inject code into the Streams module's going live message. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. As a workaround, unloading the Trivia module with `unload streams` can render this exploit not accessible. It is highly recommended updating to 3.3.12 or 3.4 to completely patch this issue.

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19184

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19183

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    8.2
    High

    CVE-2020-15140

    Last Modified: 21 Nov 2024

    In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical exploit has been fixed on version 3.3.11.

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19181

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19179

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19178

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19173

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19123

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19121

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    —
    Unknown

    CVE-2019-19120

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Aug 2020
    5.4
    Medium

    CVE-2020-20633

    Last Modified: 21 Nov 2024

    ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.

    Published: 21 Aug 2020
    6.8
    Medium

    CVE-2020-10290

    Last Modified: 21 Nov 2024

    Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that presents many primitives that can compromise the overall robot operations as demonstrated in our video. In our PoC we demonstrate how a malicious actor could 'cook' a custom URCap that when deployed by the user (intendedly or unintendedly) compromises the system

    Published: 21 Aug 2020
    6.5
    Medium

    CVE-2020-20634

    Last Modified: 21 Nov 2024

    Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

    Published: 21 Aug 2020
    8.8
    High

    CVE-2020-24057

    Last Modified: 21 Nov 2024

    The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated attacker can leverage this issue to execute arbitrary commands as 'root'.

    Published: 21 Aug 2020
    7.5
    High

    CVE-2020-24056

    Last Modified: 21 Nov 2024

    A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

    Published: 21 Aug 2020
    9.8
    Critical

    CVE-2020-24055

    Last Modified: 21 Nov 2024

    Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.

    Published: 21 Aug 2020
    9.8
    Critical

    CVE-2020-24054

    Last Modified: 21 Nov 2024

    The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary without arguments; however, this can be circumvented using special shell variables, such as '${IFS}'. As a result, an attacker can execute arbitrary commands as 'root' on the units.

    Published: 21 Aug 2020
    7.5
    High

    CVE-2020-24053

    Last Modified: 21 Nov 2024

    Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

    Published: 21 Aug 2020
    9.1
    Critical

    CVE-2020-24052

    Last Modified: 21 Nov 2024

    Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

    Published: 21 Aug 2020
    9.8
    Critical

    CVE-2020-24051

    Last Modified: 21 Nov 2024

    The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute privileged operations without authentication, for instance, to create a new Administrator user.

    Published: 21 Aug 2020
    6.5
    Medium

    CVE-2020-9246

    Last Modified: 21 Nov 2024

    FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some extra information. This can lead to information leak.

    Published: 21 Aug 2020
    5.5
    Medium

    CVE-2020-9095

    Last Modified: 21 Nov 2024

    HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause integer overflow. This can compromise normal service.

    Published: 21 Aug 2020
    5.5
    Medium

    CVE-2020-9096

    Last Modified: 21 Nov 2024

    HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.

    Published: 21 Aug 2020
    7
    High

    CVE-2020-15309

    Last Modified: 21 Nov 2024

    An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against public key operations. These attackers may already have obtained sensitive information if the affected system has been used for private key operations (e.g., signing with a private key).

    Published: 21 Aug 2020
    4.3
    Medium

    CVE-2020-9104

    Last Modified: 21 Nov 2024

    HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),Versions earlier than 10.1.0.126(C10E7R5P1),Versions earlier than 10.1.0.126(C185E4R7P1),Versions earlier than 10.1.0.126(C461E7R3P1),Versions earlier than 10.1.0.126(C605E19R1P3),Versions earlier than 10.1.0.126(C636E7R3P4),Versions earlier than 10.1.0.128(C635E3R2P4),Versions earlier than 10.1.0.160(C00E160R2P11),Versions earlier than 10.1.0.160(C01E160R2P11) have a denial of service vulnerability. In specific scenario, due to the improper resource management and memory leak of some feature, the attacker could exploit this vulnerability to cause the device reset.

    Published: 21 Aug 2020
    7.5
    High

    CVE-2020-12457

    Last Modified: 21 Nov 2024

    An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way involving more than one in a row, the server becomes stuck in the ProcessReply() loop, i.e., a denial of service.

    Published: 21 Aug 2020
    5.3
    Medium

    CVE-2020-24585

    Last Modified: 21 Nov 2024

    An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messages in epoch 0 do not produce an out-of-order error. Instead, these messages are returned to the application.

    Published: 21 Aug 2020
    5.3
    Medium

    CVE-2020-3976

    Last Modified: 21 Nov 2024

    VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

    Published: 21 Aug 2020
    7.1
    High

    CVE-2020-5774

    Last Modified: 21 Nov 2024

    Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser session.

    Published: 21 Aug 2020
    4.9
    Medium

    CVE-2020-16239

    Last Modified: 4 Jun 2025

    When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.

    Published: 21 Aug 2020
    6.3
    Medium

    CVE-2020-16241

    Last Modified: 4 Jun 2025

    Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    Published: 21 Aug 2020
    2.1
    Low

    CVE-2020-16237

    Last Modified: 4 Jun 2025

    Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

    Published: 21 Aug 2020
    5.3
    Medium

    CVE-2020-14518

    Last Modified: 4 Jun 2025

    Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

    Published: 21 Aug 2020
    8.1
    High

    CVE-2020-7710

    Last Modified: 21 Nov 2024

    This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

    Published: 21 Aug 2020