CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-5873

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.

    Published: 30 Apr 2020
    7.5
    High

    CVE-2020-5874

    Last Modified: 21 Nov 2024

    On BIG-IP APM 15.0.0-15.0.1.2, 14.1.0-14.1.2.3, and 14.0.0-14.0.1, in certain circumstances, an attacker sending specifically crafted requests to a BIG-IP APM virtual server may cause a disruption of service provided by the Traffic Management Microkernel(TMM).

    Published: 30 Apr 2020
    7.5
    High

    CVE-2020-5872

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.2.3, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.4.1, when processing TLS traffic with hardware cryptographic acceleration enabled on platforms with Intel QAT hardware, the Traffic Management Microkernel (TMM) may stop responding and cause a failover event.

    Published: 30 Apr 2020
    7.5
    High

    CVE-2020-5871

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occur when ciphers, which have been blacklisted by the HTTP/2 RFC, are used on backend servers. This is a data-plane issue. There is no control-plane exposure.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2019-0235

    Last Modified: 21 Nov 2024

    Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

    Published: 30 Apr 2020
    7.5
    High

    CVE-2019-12425

    Last Modified: 21 Nov 2024

    Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

    Published: 30 Apr 2020
    9.8
    Critical

    CVE-2020-7136

    Last Modified: 21 Nov 2024

    A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

    Published: 30 Apr 2020
    7.5
    High

    CVE-2020-11015

    Last Modified: 23 Apr 2025

    A vulnerability has been disclosed in thinx-device-api IoT Device Management Server before version 2.5.0. Device MAC address can be spoofed. This means initial registration requests without UDID and spoofed MAC address may pass to create new UDID with same MAC address. Full impact needs to be reviewed further. Applies to all (mostly ESP8266/ESP32) users. This has been fixed in firmware version 2.5.0.

    Published: 30 Apr 2020
    7
    High

    CVE-2020-12050

    Last Modified: 21 Nov 2024

    SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2020-6010

    Last Modified: 21 Nov 2024

    LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

    Published: 30 Apr 2020
    4.3
    Medium

    CVE-2020-12101

    Last Modified: 21 Nov 2024

    The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2019-19215

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2019-19216

    Last Modified: 21 Nov 2024

    BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2019-19217

    Last Modified: 21 Nov 2024

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.

    Published: 30 Apr 2020
    7.5
    High

    CVE-2019-19218

    Last Modified: 21 Nov 2024

    BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.

    Published: 30 Apr 2020
    7.5
    High

    CVE-2019-19219

    Last Modified: 21 Nov 2024

    BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.

    Published: 30 Apr 2020
    8.8
    High

    CVE-2019-19220

    Last Modified: 21 Nov 2024

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).

    Published: 30 Apr 2020
    6.1
    Medium

    CVE-2020-6579

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in mailhive/cloudbeez/cloudloader.php and mailhive/cloudbeez/cloudloader_core.php in the MailBeez plugin for ZenCart before 3.9.22 allows remote attackers to inject arbitrary web script or HTML via the cloudloader_mode parameter.

    Published: 30 Apr 2020
    4.3
    Medium

    CVE-2020-9387

    Last Modified: 21 Nov 2024

    In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

    Published: 30 Apr 2020
    6.1
    Medium

    CVE-2020-12283

    Last Modified: 21 Nov 2024

    Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.

    Published: 30 Apr 2020
    6.6
    Medium

    CVE-2019-10169

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12537

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12538

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12549

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12560

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12569

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12570

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    6.6
    Medium

    CVE-2019-10170

    Last Modified: 21 Nov 2024

    A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.

    Published: 30 Apr 2020
    6.5
    Medium

    CVE-2020-13143

    Last Modified: 21 Nov 2024

    gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12548

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12559

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12590

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    6.3
    Medium

    CVE-2020-10706

    Last Modified: 21 Nov 2024

    A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into the cluster via the WebUI or via the command line in the last 24 hours. Once the backup is older than 24 hours the OAuth tokens are no longer valid.

    Published: 30 Apr 2020
    3.3
    Low

    CVE-2020-10717

    Last Modified: 21 Nov 2024

    A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest via virtio-fs device. If the guest opens the maximum number of file descriptors under the shared directory, a denial of service may occur. This flaw allows a guest user/process to cause this denial of service on the host.

    Published: 30 Apr 2020
    7.8
    High

    CVE-2020-10728

    Last Modified: 21 Nov 2024

    A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 30 Apr 2020
    6.1
    Medium

    CVE-2020-11027

    Last Modified: 21 Nov 2024

    In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12515

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12520

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12531

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12532

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12533

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12534

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12535

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12536

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12539

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12540

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12541

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12543

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020
    —
    Unknown

    CVE-2020-12544

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 30 Apr 2020