CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-10378

    Last Modified: 21 Nov 2024

    In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

    Published: 25 Jun 2020
    7.8
    High

    CVE-2020-10379

    Last Modified: 21 Nov 2024

    In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

    Published: 25 Jun 2020
    5.4
    Medium

    CVE-2020-10753

    Last Modified: 21 Nov 2024

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.

    Published: 25 Jun 2020
    8.8
    High

    CVE-2020-15046

    Last Modified: 21 Nov 2024

    The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.

    Published: 24 Jun 2020
    4.8
    Medium

    CVE-2020-15041

    Last Modified: 21 Nov 2024

    PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.

    Published: 24 Jun 2020
    7.8
    High

    CVE-2020-5962

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-15038

    Last Modified: 21 Nov 2024

    The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.

    Published: 24 Jun 2020
    7.3
    High

    CVE-2020-13247

    Last Modified: 21 Nov 2024

    BooleBox Secure File Sharing Utility before 4.2.3.0 allows CSV injection via a crafted user name that is mishandled during export from the activity logs in the Audit Area.

    Published: 24 Jun 2020
    4.9
    Medium

    CVE-2020-15026

    Last Modified: 21 Nov 2024

    Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-13248

    Last Modified: 21 Nov 2024

    BooleBox Secure File Sharing Utility before 4.2.3.0 allows stored XSS via a crafted avatar field within My Account JSON data to Account.aspx.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-14472

    Last Modified: 21 Nov 2024

    On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-14473

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10561

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-11961

    Last Modified: 21 Nov 2024

    Xiaomi router R3600 ROM before 1.0.50 is affected by a sensitive information leakage caused by an insecure interface get_config_result without authentication

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-11960

    Last Modified: 21 Nov 2024

    Xiaomi router R3600 ROM before 1.0.50 is affected by a vulnerability when checking backup file in c_upload interface let attacker able to extract malicious file under any location in /tmp, lead to possible RCE and DoS

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-11959

    Last Modified: 21 Nov 2024

    An unsafe configuration of nginx lead to information leak in Xiaomi router R3600 ROM before 1.0.50.

    Published: 24 Jun 2020
    8.2
    High

    CVE-2020-3962

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain a use-after-free vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine.

    Published: 24 Jun 2020
    7.8
    High

    CVE-2020-3969

    Last Modified: 21 Nov 2024

    VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an off-by-one heap-overflow vulnerability in the SVGA device. A malicious actor with local access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine. Additional conditions beyond the attacker's control must be present for exploitation to be possible.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-14094

    Last Modified: 21 Nov 2024

    In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.

    Published: 24 Jun 2020
    8
    High

    CVE-2020-6870

    Last Modified: 21 Nov 2024

    The version V12.17.20T115 of ZTE U31R20 product is impacted by a design error vulnerability. An attacker could exploit the vulnerability to log in to the FTP server to tamper with the password, and illegally download, modify, upload, or delete files, causing improper operation of the network management system and equipment. This affects: NetNumenU31R20 V12.17.20T115

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-9494

    Last Modified: 21 Nov 2024

    Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-14095

    Last Modified: 21 Nov 2024

    In Xiaomi router R3600, ROM version<1.0.20, a connect service suffers from an injection vulnerability through the web interface, leading to a stack overflow or remote code execution.

    Published: 24 Jun 2020
    8.8
    High

    CVE-2020-13443

    Last Modified: 21 Nov 2024

    ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new files. Short aliases are not used for an attachment; instead, direct access is allowed to the uploaded files. It is possible to upload PHP only if one has member access, or registration/forum is enabled and one can create a member with the default group id of 5. To exploit this, one must to be able to send and compose messages (at least).

    Published: 24 Jun 2020
    6.1
    Medium

    CVE-2020-13483

    Last Modified: 21 Nov 2024

    The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-13484

    Last Modified: 21 Nov 2024

    Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-13700

    Last Modified: 21 Nov 2024

    An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.

    Published: 24 Jun 2020
    6.1
    Medium

    CVE-2020-14018

    Last Modified: 21 Nov 2024

    An issue was discovered in Navigate CMS 2.9 r1433. There is a stored XSS vulnerability that is executed on the page to view users, and on the page to edit users. This is present in both the User field and the E-Mail field. On the Edit user page, the XSS is only triggered via the E-Mail field; however, on the View user page the XSS is triggered via either the User field or the E-Mail field.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-14017

    Last Modified: 21 Nov 2024

    An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing sessions, or view the contents of this file to discover details about a session.

    Published: 24 Jun 2020
    5.3
    Medium

    CVE-2020-14016

    Last Modified: 21 Nov 2024

    An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to reset their passwords by using either their username or the email address associated with their account. However, the feature returns a not_found message when the provided username or email address does not match a user in the system. This can be used to enumerate users.

    Published: 24 Jun 2020
    6.1
    Medium

    CVE-2020-15015

    Last Modified: 21 Nov 2024

    The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-14015

    Last Modified: 21 Nov 2024

    An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-14014

    Last Modified: 21 Nov 2024

    An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.

    Published: 24 Jun 2020
    5.9
    Medium

    CVE-2020-4413

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 179988.

    Published: 24 Jun 2020
    5.3
    Medium

    CVE-2020-4342

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could disclose sensitive information included in installation files to an unauthorized user. IBM X-Force ID: 178182.

    Published: 24 Jun 2020
    5.3
    Medium

    CVE-2020-4341

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 178181.

    Published: 24 Jun 2020
    5.3
    Medium

    CVE-2020-4327

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 177599.

    Published: 24 Jun 2020
    6.1
    Medium

    CVE-2020-4323

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 177514.

    Published: 24 Jun 2020
    4.3
    Medium

    CVE-2020-4322

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 177511.

    Published: 24 Jun 2020
    8.8
    High

    CVE-2020-14005

    Last Modified: 21 Nov 2024

    Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-14006

    Last Modified: 21 Nov 2024

    Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-14007

    Last Modified: 21 Nov 2024

    Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.

    Published: 24 Jun 2020
    6.5
    Medium

    CVE-2020-15018

    Last Modified: 21 Nov 2024

    playSMS through 1.4.3 is vulnerable to session fixation.

    Published: 24 Jun 2020
    2.2
    Low

    CVE-2020-4071

    Last Modified: 21 Nov 2024

    In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set. Currently the string comparison between configured credentials and the ones provided by users is performed through a character-by-character string comparison. This enables a possibility that attacker may time the time it takes the server to validate different usernames and password, and use this knowledge to work out the valid credentials. This attack is understood not to be realistic over the Internet. However, it may be achieved from within local networks where the website is hosted, e.g. from inside a data centre where a website's server is located. Sites protected by IP address whitelisting only are unaffected by this vulnerability. This vulnerability has been fixed on version 0.3.4 of django-basic-auth-ip-whitelist. Update to version 0.3.4 as soon as possible and change basic authentication username and password configured on a Django project using this package. A workaround without upgrading to version 0.3.4 is to stop using basic authentication and use the IP whitelisting component only. It can be achieved by not setting BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD in Django project settings.

    Published: 24 Jun 2020
    8.8
    High

    CVE-2020-15014

    Last Modified: 21 Nov 2024

    pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-7667

    Last Modified: 21 Nov 2024

    In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions which were re-released.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-15007

    Last Modified: 21 Nov 2024

    A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.

    Published: 24 Jun 2020
    5.4
    Medium

    CVE-2020-15006

    Last Modified: 21 Nov 2024

    Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10279

    Last Modified: 21 Nov 2024

    MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were granted via file creation, access race conditions, insecure home directory configurations and defaults that facilitate Denial of Service (DoS) attacks.

    Published: 24 Jun 2020
    7.5
    High

    CVE-2020-10280

    Last Modified: 21 Nov 2024

    The Apache server on port 80 that host the web interface is vulnerable to a DoS by spamming incomplete HTTP headers, effectively blocking the access to the dashboard.

    Published: 24 Jun 2020
    9.8
    Critical

    CVE-2020-10269

    Last Modified: 21 Nov 2024

    One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. We have confirmed this flaw in MiR100 and MiR200 but it might also apply to MiR250, MiR500 and MiR1000.

    Published: 24 Jun 2020