CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-13144

    Last Modified: 21 Nov 2024

    Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.

    Published: 18 May 2020
    6.1
    Medium

    CVE-2019-19456

    Last Modified: 21 Nov 2024

    A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

    Published: 18 May 2020
    7.5
    High

    CVE-2019-19454

    Last Modified: 21 Nov 2024

    An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

    Published: 18 May 2020
    5.5
    Medium

    CVE-2020-6093

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting in information disclosure. In order to trigger this vulnerability, victim must open a malicious file.

    Published: 18 May 2020
    7.8
    High

    CVE-2020-6092

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lead to arbitrary code execution. In order to trigger this vulnerability, victim must open a malicious file.

    Published: 18 May 2020
    8.8
    High

    CVE-2020-6074

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 18 May 2020
    6.1
    Medium

    CVE-2020-8034

    Last Modified: 21 Nov 2024

    Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.

    Published: 18 May 2020
    6.5
    Medium

    CVE-2020-13135

    Last Modified: 21 Nov 2024

    D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-13136

    Last Modified: 21 Nov 2024

    D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.

    Published: 18 May 2020
    6.7
    Medium

    CVE-2019-7246

    Last Modified: 21 Nov 2024

    An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. The vulnerable driver exposes a wrmsr instruction and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

    Published: 18 May 2020
    9.8
    Critical

    CVE-2019-7247

    Last Modified: 21 Nov 2024

    An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x81112ee0 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

    Published: 18 May 2020
    8.8
    High

    CVE-2020-11549

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The root account has the same password as the Web-admin component. Thus, by exploiting CVE-2020-11551, it is possible to achieve remote code execution with root privileges on the embedded Linux system.

    Published: 18 May 2020
    6.5
    Medium

    CVE-2020-11550

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote leak of sensitive/arbitrary Wi-Fi information, such as SSIDs and Pre-Shared-Keys (PSK).

    Published: 18 May 2020
    8.8
    High

    CVE-2020-11551

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and Pro Tri-Band Business WiFi Router (SRR60) AC3000 V2.5.1.106. The administrative SOAP interface allows an unauthenticated remote write of arbitrary Wi-Fi configuration data such as authentication details (e.g., the Web-admin password), network settings, DNS settings, system administration interface configuration, etc.

    Published: 18 May 2020
    6.1
    Medium

    CVE-2020-8035

    Last Modified: 21 Nov 2024

    The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.

    Published: 18 May 2020
    5.3
    Medium

    CVE-2020-12801

    Last Modified: 21 Nov 2024

    If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document was not LibreOffice's default ODF file format, then affected versions of LibreOffice default that subsequent saves of the document are unencrypted. This may lead to a user accidentally saving a MSOffice file format document unencrypted while believing it to be encrypted. This issue affects: LibreOffice 6-3 series versions prior to 6.3.6; 6-4 series versions prior to 6.4.3.

    Published: 18 May 2020
    8.8
    High

    CVE-2020-12255

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering the file extension and header. Thus, an attacker can exploit this by uploading a .php file to vendor.php that contains arbitrary PHP code and changing the content-type to image/gif.

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-12256

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.

    Published: 18 May 2020
    8.8
    High

    CVE-2020-12257

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a form (add a user, delete a user, or edit a user).

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-9524

    Last Modified: 21 Nov 2024

    Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to version 5.0 Patch Update 8. The vulnerability could allow an attacker to trigger administrative actions when an administrator viewed malicious data left by the attacker (stored XSS) or followed a malicious link (reflected XSS).

    Published: 18 May 2020
    9.1
    Critical

    CVE-2020-12258

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-12259

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.

    Published: 18 May 2020
    7.2
    High

    CVE-2020-13129

    Last Modified: 21 Nov 2024

    An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string, which allows attackers to obtain sensitive information by reading web-server logs.

    Published: 18 May 2020
    5.3
    Medium

    CVE-2020-12860

    Last Modified: 21 Nov 2024

    COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identification of a device, and potentially identification of the owner's name.

    Published: 18 May 2020
    5.3
    Medium

    CVE-2020-12859

    Last Modified: 21 Nov 2024

    Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common phone models or those in low-density situations.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-12858

    Last Modified: 21 Nov 2024

    Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scanning for their advertising beacons.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-12857

    Last Modified: 21 Nov 2024

    Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.

    Published: 18 May 2020
    9.8
    Critical

    CVE-2020-12856

    Last Modified: 21 Nov 2024

    OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

    Published: 18 May 2020
    6.3
    Medium

    CVE-2020-10134

    Last Modified: 21 Nov 2024

    Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer device and an end-user erroneously completes both pairing procedures with the MITM using the confirmation number of one peer as the passkey of the other. An adjacent, unauthenticated attacker could be able to initiate any Bluetooth operation on either attacked device exposed by the enabled Bluetooth profiles. This exposure may be limited when the user must authorize certain access explicitly, but so long as a user assumes that it is the intended remote device requesting permissions, device-local protections may be weakened.

    Published: 18 May 2020
    5.4
    Medium

    CVE-2020-10135

    Last Modified: 21 Nov 2024

    Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may allow an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key.

    Published: 18 May 2020
    5.1
    Medium

    CVE-2020-10723

    Last Modified: 21 Nov 2024

    A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

    Published: 18 May 2020
    5.1
    Medium

    CVE-2020-10724

    Last Modified: 21 Nov 2024

    A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-10957

    Last Modified: 21 Nov 2024

    In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.

    Published: 18 May 2020
    8.8
    High

    CVE-2019-14836

    Last Modified: 21 Nov 2024

    A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

    Published: 18 May 2020
    9.8
    Critical

    CVE-2020-8165

    Last Modified: 9 May 2025

    A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-8162

    Last Modified: 21 Nov 2024

    A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

    Published: 18 May 2020
    5.3
    Medium

    CVE-2020-10967

    Last Modified: 21 Nov 2024

    In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

    Published: 18 May 2020
    5.1
    Medium

    CVE-2020-10722

    Last Modified: 21 Nov 2024

    A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.

    Published: 18 May 2020
    7.7
    High

    CVE-2020-10725

    Last Modified: 21 Nov 2024

    A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

    Published: 18 May 2020
    6
    Medium

    CVE-2020-10726

    Last Modified: 21 Nov 2024

    A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

    Published: 18 May 2020
    8
    High

    CVE-2020-10736

    Last Modified: 21 Nov 2024

    An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.

    Published: 18 May 2020
    5.3
    Medium

    CVE-2020-10958

    Last Modified: 21 Nov 2024

    In Dovecot before 2.3.10.1, a crafted SMTP/LMTP message triggers an unauthenticated use-after-free bug in submission-login, submission, or lmtp, and can lead to a crash under circumstances involving many newlines after a command.

    Published: 18 May 2020
    6.5
    Medium

    CVE-2020-8167

    Last Modified: 21 Nov 2024

    A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

    Published: 18 May 2020
    4.3
    Medium

    CVE-2020-8166

    Last Modified: 28 Apr 2026

    A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.

    Published: 18 May 2020
    7.5
    High

    CVE-2020-8164

    Last Modified: 21 Nov 2024

    A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.

    Published: 18 May 2020
    7.5
    High

    CVE-2019-20797

    Last Modified: 21 Nov 2024

    An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for handling received UDP packets, as demonstrated by I_SendPacket or I_SendPacketTo in i_network.c.

    Published: 17 May 2020
    8.4
    High

    CVE-2019-20798

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. The XSS in the administrator panel can be used to reconfigure the server and execute arbitrary commands.

    Published: 17 May 2020
    7.5
    High

    CVE-2019-20799

    Last Modified: 21 Nov 2024

    In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.

    Published: 17 May 2020
    9.8
    Critical

    CVE-2019-20800

    Last Modified: 21 Nov 2024

    In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.

    Published: 17 May 2020
    5.3
    Medium

    CVE-2019-20801

    Last Modified: 21 Nov 2024

    An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

    Published: 17 May 2020