CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-20802

    Last Modified: 21 Nov 2024

    An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker.

    Published: 17 May 2020
    7.5
    High

    CVE-2020-13128

    Last Modified: 21 Nov 2024

    An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service.

    Published: 17 May 2020
    3.3
    Low

    CVE-2020-4345

    Last Modified: 21 Nov 2024

    IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.

    Published: 17 May 2020
    6.5
    Medium

    CVE-2020-13125

    Last Modified: 21 Nov 2024

    An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers can create users with the Subscriber role even if registration is disabled.

    Published: 17 May 2020
    9.9
    Critical

    CVE-2020-13126

    Last Modified: 21 Nov 2024

    An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can upload arbitrary executable files to achieve remote code execution. NOTE: the free Elementor plugin is unaffected.

    Published: 17 May 2020
    8.8
    High

    CVE-2020-12861

    Last Modified: 21 Nov 2024

    A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.

    Published: 17 May 2020
    8
    High

    CVE-2020-12865

    Last Modified: 21 Nov 2024

    A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.

    Published: 17 May 2020
    5.7
    Medium

    CVE-2020-12866

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.

    Published: 17 May 2020
    4.3
    Medium

    CVE-2020-12862

    Last Modified: 21 Nov 2024

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.

    Published: 17 May 2020
    4.3
    Medium

    CVE-2020-12863

    Last Modified: 21 Nov 2024

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.

    Published: 17 May 2020
    4.3
    Medium

    CVE-2020-12864

    Last Modified: 21 Nov 2024

    An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.

    Published: 17 May 2020
    6.1
    Medium

    CVE-2020-13121

    Last Modified: 21 Nov 2024

    Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.

    Published: 16 May 2020
    9.8
    Critical

    CVE-2020-13118

    Last Modified: 21 Nov 2024

    An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

    Published: 16 May 2020
    7.5
    High

    CVE-2020-13111

    Last Modified: 21 Nov 2024

    NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer request that will result in a negative value being passed to memmove via the size parameter, causing the process to crash.

    Published: 16 May 2020
    7.8
    High

    CVE-2020-13110

    Last Modified: 21 Nov 2024

    The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.

    Published: 16 May 2020
    9.8
    Critical

    CVE-2020-13109

    Last Modified: 21 Nov 2024

    Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to top-level command 7) has a stack-based buffer overflow.

    Published: 16 May 2020
    9.1
    Critical

    CVE-2020-13112

    Last Modified: 21 Nov 2024

    An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093.

    Published: 16 May 2020
    8.2
    High

    CVE-2020-13113

    Last Modified: 21 Nov 2024

    An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.

    Published: 16 May 2020
    7
    High

    CVE-2020-13630

    Last Modified: 21 Nov 2024

    ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

    Published: 16 May 2020
    7.5
    High

    CVE-2020-13114

    Last Modified: 21 Nov 2024

    An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data.

    Published: 16 May 2020
    6.5
    Medium

    CVE-2018-21270

    Last Modified: 21 Nov 2024

    Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

    Published: 16 May 2020
    5.3
    Medium

    CVE-2020-13093

    Last Modified: 21 Nov 2024

    iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-8149

    Last Modified: 21 Nov 2024

    Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-13091

    Last Modified: 21 Nov 2024

    pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-13092

    Last Modified: 21 Nov 2024

    scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

    Published: 15 May 2020
    5.5
    Medium

    CVE-2020-12872

    Last Modified: 21 Nov 2024

    yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-12889

    Last Modified: 21 Nov 2024

    MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.

    Published: 15 May 2020
    7.8
    High

    CVE-2020-12798

    Last Modified: 21 Nov 2024

    Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-12651

    Last Modified: 21 Nov 2024

    SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.

    Published: 15 May 2020
    7.8
    High

    CVE-2019-19721

    Last Modified: 21 Nov 2024

    An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2019-18666

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.

    Published: 15 May 2020
    8.1
    High

    CVE-2019-20390

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An attacker can craft a panel/uploads/read.json?cmd=rm URL (removing this token) and send it to the victim.

    Published: 15 May 2020
    6.1
    Medium

    CVE-2019-20389

    Last Modified: 21 Nov 2024

    An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within multipart/form-data), which is reflected back within a user's browser without proper output encoding.

    Published: 15 May 2020
    6.1
    Medium

    CVE-2020-12685

    Last Modified: 21 Nov 2024

    XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-12834

    Last Modified: 21 Nov 2024

    eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

    Published: 15 May 2020
    7.8
    High

    CVE-2018-10756

    Last Modified: 21 Nov 2024

    Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.

    Published: 15 May 2020
    4.4
    Medium

    CVE-2020-7809

    Last Modified: 21 Nov 2024

    ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could exploit this vulnerability by tricking the victim to open ALSong Album(sab) file.

    Published: 15 May 2020
    2.4
    Low

    CVE-2020-9073

    Last Modified: 21 Nov 2024

    Huawei P20 smartphones with versions earlier than 10.0.0.156(C00E156R1P4) have an improper authentication vulnerability. The vulnerability is due to that when an user wants to do certain operation, the software insufficiently validate the user's identity. Attackers need to physically access the smartphone to exploit this vulnerability. Successful exploit could allow the attacker to bypass the limit of student mode function.

    Published: 15 May 2020
    7.1
    High

    CVE-2020-1808

    Last Modified: 21 Nov 2024

    Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.176(C00E60R2P11);9.1.0.135(C00E133R2P1); versions earlier than 10.1.0.123(C431E22R3P5), versions earlier than 10.1.0.126(C636E5R3P4), versions earlier than 10.1.0.160(C00E160R2P11); versions earlier than 10.1.0.126(C185E8R5P1), versions earlier than 10.1.0.126(C636E9R2P4), versions earlier than 10.1.0.160(C00E160R2P8); versions earlier than 10.0.0.179(C636E3R4P3), versions earlier than 10.0.0.180(C185E3R3P3), versions earlier than 10.0.0.180(C432E10R3P4), versions earlier than 10.0.0.181(C675E5R1P2) have an out of bound read vulnerability. The software reads data past the end of the intended buffer. The attacker tricks the user into installing a crafted application, successful exploit may cause information disclosure or service abnormal.

    Published: 15 May 2020
    5.5
    Medium

    CVE-2020-3810

    Last Modified: 21 Nov 2024

    Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.

    Published: 15 May 2020
    9
    Critical

    CVE-2020-8100

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker to trigger a denial of service while scanning a specially-crafted sample. This issue affects: Bitdefender Bitdefender Engines versions prior to 7.84063.

    Published: 15 May 2020
    5.4
    Medium

    CVE-2020-12882

    Last Modified: 21 Nov 2024

    Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.

    Published: 15 May 2020
    3.3
    Low

    CVE-2020-11931

    Last Modified: 21 Nov 2024

    An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;

    Published: 15 May 2020
    3.9
    Low

    CVE-2020-13361

    Last Modified: 21 Nov 2024

    In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.

    Published: 15 May 2020
    4.4
    Medium

    CVE-2020-14304

    Last Modified: 21 Nov 2024

    A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.

    Published: 15 May 2020
    5.4
    Medium

    CVE-2020-7069

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.

    Published: 15 May 2020
    8.8
    High

    CVE-2020-8163

    Last Modified: 21 Nov 2024

    The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.

    Published: 15 May 2020
    7.5
    High

    CVE-2020-5410

    Last Modified: 3 Nov 2025

    Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.

    Published: 15 May 2020
    9.8
    Critical

    CVE-2020-10620

    Last Modified: 21 Nov 2024

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.

    Published: 14 May 2020
    8.8
    High

    CVE-2020-10616

    Last Modified: 21 Nov 2024

    Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker can replace them and execute code whenever the service starts.

    Published: 14 May 2020