CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2020-12388

    Last Modified: 21 Nov 2024

    The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

    Published: 5 May 2020
    7.8
    High

    CVE-2020-12393

    Last Modified: 21 Nov 2024

    The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

    Published: 5 May 2020
    3.3
    Low

    CVE-2020-12394

    Last Modified: 21 Nov 2024

    A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. This vulnerability affects Firefox < 76.

    Published: 5 May 2020
    9.8
    Critical

    CVE-2020-12395

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

    Published: 5 May 2020
    6.7
    Medium

    CVE-2020-12659

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.

    Published: 5 May 2020
    7.5
    High

    CVE-2020-12783

    Last Modified: 21 Nov 2024

    Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.

    Published: 5 May 2020
    8.8
    High

    CVE-2020-6464

    Last Modified: 21 Nov 2024

    Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 May 2020
    9.8
    Critical

    CVE-2020-6831

    Last Modified: 21 Nov 2024

    A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

    Published: 5 May 2020
    7.5
    High

    CVE-2022-27385

    Last Modified: 21 Nov 2024

    An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

    Published: 5 May 2020
    7.3
    High

    CVE-2020-5343

    Last Modified: 21 Nov 2024

    Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access on the root folder.

    Published: 4 May 2020
    4.6
    Medium

    CVE-2020-5337

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.

    Published: 4 May 2020
    4.6
    Medium

    CVE-2020-5336

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.

    Published: 4 May 2020
    5
    Medium

    CVE-2020-5335

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the privileges of the authenticated victim user.

    Published: 4 May 2020
    8.2
    High

    CVE-2020-5334

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is then executed by the web browser in the context of the vulnerable web application.

    Published: 4 May 2020
    4.3
    Medium

    CVE-2020-5333

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to view unauthorized information.

    Published: 4 May 2020
    7.2
    High

    CVE-2020-5332

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain a command injection vulnerability. AN authenticated malicious user with administrator privileges could potentially exploit this vulnerability to execute arbitrary commands on the system where the vulnerable application is deployed.

    Published: 4 May 2020
    8.8
    High

    CVE-2020-5331

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an information exposure vulnerability. Users’ session information could potentially be stored in cache or log files. An authenticated malicious local user with access to the log files may obtain the exposed information to use it in further attacks.

    Published: 4 May 2020
    7.8
    High

    CVE-2020-10622

    Last Modified: 21 Nov 2024

    LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users

    Published: 4 May 2020
    5.5
    Medium

    CVE-2020-10618

    Last Modified: 21 Nov 2024

    LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.

    Published: 4 May 2020
    —
    Unknown

    CVE-2017-18774

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-21139, CVE-2017-18867. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2018-21139 and CVE-2017-18867 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 May 2020
    —
    Unknown

    CVE-2017-18771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20738, CVE-2017-18866. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2019-20738 and CVE-2017-18866 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 May 2020
    —
    Unknown

    CVE-2017-18760

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20732, CVE-2017-18865. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2019-20732 and CVE-2017-18865 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 May 2020
    —
    Unknown

    CVE-2017-18753

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20734, CVE-2017-18864. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2019-20734 and CVE-2017-18864 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 May 2020
    7.5
    High

    CVE-2020-12642

    Last Modified: 21 Nov 2024

    An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.

    Published: 4 May 2020
    8.8
    High

    CVE-2020-12109

    Last Modified: 21 Nov 2024

    Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-12640

    Last Modified: 21 Nov 2024

    Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-12641

    Last Modified: 4 Nov 2025

    rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

    Published: 4 May 2020
    6.5
    Medium

    CVE-2018-21233

    Last Modified: 21 Nov 2024

    TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the contents of process memory. This occurs in the DecodeBmp feature of the BMP decoder in core/kernels/decode_bmp_op.cc.

    Published: 4 May 2020
    8.8
    High

    CVE-2020-12111

    Last Modified: 21 Nov 2024

    Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-12110

    Last Modified: 21 Nov 2024

    Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

    Published: 4 May 2020
    7.5
    High

    CVE-2020-11462

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenVPN Access Server before 2.7.0 and 2.8.x before 2.8.3. With the full featured RPC2 interface enabled, it is possible to achieve a temporary DoS state of the management interface when sending an XML Entity Expansion (XEE) payload to the XMLRPC based RPC2 interface. The duration of the DoS state depends on available memory and CPU speed. The default restricted mode of the RPC2 interface is NOT vulnerable.

    Published: 4 May 2020
    8.1
    High

    CVE-2020-11443

    Last Modified: 21 Nov 2024

    The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the machine. As the installer runs with SYSTEM privileges and follows these links, a user can cause the installer to delete files that otherwise cannot be deleted by the user.

    Published: 4 May 2020
    6.1
    Medium

    CVE-2020-12639

    Last Modified: 21 Nov 2024

    phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.

    Published: 4 May 2020
    7.5
    High

    CVE-2019-13285

    Last Modified: 21 Nov 2024

    CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

    Published: 4 May 2020
    5.5
    Medium

    CVE-2020-12475

    Last Modified: 21 Nov 2024

    TP-Link Omada Controller Software 3.2.6 allows Directory Traversal for reading arbitrary files via com.tp_link.eap.web.portal.PortalController.getAdvertiseFile in /opt/tplink/EAPController/lib/eap-web-3.2.6.jar.

    Published: 4 May 2020
    5.3
    Medium

    CVE-2020-8792

    Last Modified: 21 Nov 2024

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by its barcode reveals the email address of the account to which the lock is bound, as well as the name of the lock. Valid barcode inputs can be easily guessed because barcode strings follow a predictable pattern. Correctly guessed valid barcode inputs entered through the app interface disclose arbitrary users' email addresses and lock names.

    Published: 4 May 2020
    5.5
    Medium

    CVE-2019-12864

    Last Modified: 21 Nov 2024

    SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

    Published: 4 May 2020
    5.4
    Medium

    CVE-2020-4209

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to create arbitrary files on the system. IBM X-Force ID: 175019.

    Published: 4 May 2020
    8.1
    High

    CVE-2020-11671

    Last Modified: 21 Nov 2024

    Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.

    Published: 4 May 2020
    4.2
    Medium

    CVE-2020-8896

    Last Modified: 21 Nov 2024

    A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.

    Published: 4 May 2020
    6.5
    Medium

    CVE-2020-8791

    Last Modified: 21 Nov 2024

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resulting in IDOR issues. A remote attacker can use their own token to make unauthorized API requests on behalf of arbitrary user IDs. Valid and current user IDs are trivial to guess because of the user ID assignment convention used by the app. A remote attacker could harvest email addresses, unsalted MD5 password hashes, owner-assigned lock names, and owner-assigned fingerprint names for any range of arbitrary user IDs.

    Published: 4 May 2020
    7.5
    High

    CVE-2020-10187

    Last Modified: 21 Nov 2024

    Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application owner. After authorizing the application and allowing access, the attacker simply needs to request the list of their authorized applications in a JSON format (usually GET /oauth/authorized_applications.json). An application is vulnerable if the authorized applications controller is enabled.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-8790

    Last Modified: 21 Nov 2024

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.

    Published: 4 May 2020
    7.5
    High

    CVE-2020-10876

    Last Modified: 21 Nov 2024

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excessive verification attempts. This allows an attacker to brute force the four-digit verification code in order to bypass email verification and change the password of a victim account.

    Published: 4 May 2020
    7.5
    High

    CVE-2020-11842

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in Micro Focus Verastream Host Integrator (VHI) product, affecting versions earlier than 7.8 Update 1 (7.8.49 or 7.8.0.49). The vulnerability allows an unauthenticated attackers to view information they may not have been authorized to view.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-1961

    Last Modified: 21 Nov 2024

    Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.

    Published: 4 May 2020
    5.4
    Medium

    CVE-2020-12629

    Last Modified: 21 Nov 2024

    include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.

    Published: 4 May 2020
    5.4
    Medium

    CVE-2019-17557

    Last Modified: 21 Nov 2024

    It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.

    Published: 4 May 2020
    9.8
    Critical

    CVE-2020-1959

    Last Modified: 21 Nov 2024

    A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache Syncope uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, they support different types of interpolation, including Java EL expressions. Therefore, if an attacker can inject arbitrary data in the error message template being passed, they will be able to run arbitrary Java code.

    Published: 4 May 2020
    8.4
    High

    CVE-2020-8018

    Last Modified: 21 Nov 2024

    A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc directory owned by the user This issue affects: SUSE Linux Enterprise Server 15 SP1 SLES15-SP1-CAP-Deployment-BYOS version 1.0.1 and prior versions; SLES15-SP1-CHOST-BYOS versions prior to 1.0.3 and prior versions;

    Published: 4 May 2020