CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-12479

    Last Modified: 21 Nov 2024

    TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

    Published: 29 Apr 2020
    9.8
    Critical

    CVE-2016-11061

    Last Modified: 21 Nov 2024

    Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-11943

    Last Modified: 21 Nov 2024

    An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

    Published: 29 Apr 2020
    9.8
    Critical

    CVE-2020-11942

    Last Modified: 21 Nov 2024

    An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.

    Published: 29 Apr 2020
    6.1
    Medium

    CVE-2020-11024

    Last Modified: 21 Nov 2024

    In Moonlight iOS/tvOS before 4.0.1, the pairing process is vulnerable to a man-in-the-middle attack. The bug has been fixed in Moonlight v4.0.1 for iOS and tvOS.

    Published: 29 Apr 2020
    7.8
    High

    CVE-2019-16011

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utility. The attacker must be authenticated to access the CLI utility. A successful exploit could allow the attacker to execute commands with root privileges.

    Published: 29 Apr 2020
    6.5
    Medium

    CVE-2020-12467

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie.

    Published: 29 Apr 2020
    7.8
    High

    CVE-2020-12468

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/.

    Published: 29 Apr 2020
    6.5
    Medium

    CVE-2020-12469

    Last Modified: 21 Nov 2024

    admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.

    Published: 29 Apr 2020
    7.2
    High

    CVE-2020-12470

    Last Modified: 21 Nov 2024

    MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

    Published: 29 Apr 2020
    9.8
    Critical

    CVE-2020-12471

    Last Modified: 21 Nov 2024

    MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5Upload, ModuleGallery.SilverLightUploadModule, HTML5Upload, and SilverLightUploadHandler.

    Published: 29 Apr 2020
    5.4
    Medium

    CVE-2020-12472

    Last Modified: 21 Nov 2024

    MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.

    Published: 29 Apr 2020
    7.2
    High

    CVE-2020-12473

    Last Modified: 21 Nov 2024

    MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program.

    Published: 29 Apr 2020
    6.3
    Medium

    CVE-2020-11021

    Last Modified: 21 Nov 2024

    Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.

    Published: 29 Apr 2020
    8.5
    High

    CVE-2020-11020

    Last Modified: 21 Nov 2024

    Faye (NPM, RubyGem) versions greater than 0.5.0 and before 1.0.4, 1.1.3 and 1.2.5, has the potential for authentication bypass in the extension system. The vulnerability allows any client to bypass checks put in place by server-side extensions, by appending extra segments to the message channel. It is patched in versions 1.0.4, 1.1.3 and 1.2.5.

    Published: 29 Apr 2020
    6.5
    Medium

    CVE-2020-11009

    Last Modified: 21 Nov 2024

    In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access is tightly restricted and all users on the system have access to all projects, this is not really much of an issue. If access is wider and allows login for users that do not have access to any projects, or project access is restricted, there is a larger issue. If access is meant to be restricted and secrets, sensitive data, or intellectual property are exposed in Rundeck execution output and job data, the risk becomes much higher. This vulnerability is patched in version 3.2.6

    Published: 29 Apr 2020
    5.3
    Medium

    CVE-2020-12275

    Last Modified: 21 Nov 2024

    GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.

    Published: 29 Apr 2020
    4.8
    Medium

    CVE-2020-12276

    Last Modified: 21 Nov 2024

    GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.

    Published: 29 Apr 2020
    5.3
    Medium

    CVE-2020-12277

    Last Modified: 21 Nov 2024

    GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

    Published: 29 Apr 2020
    6.1
    Medium

    CVE-2020-12462

    Last Modified: 21 Nov 2024

    The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-12461

    Last Modified: 21 Nov 2024

    PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query.

    Published: 29 Apr 2020
    8.9
    High

    CVE-2020-8775

    Last Modified: 21 Nov 2024

    Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.

    Published: 29 Apr 2020
    7.2
    High

    CVE-2019-19165

    Last Modified: 21 Nov 2024

    AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and executed by setting arguments to the activeX method. Download of Code Without Integrity Check vulnerability in ActiveX control of Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) allows ATTACKER to cause a file download to Windows user's folder and execute. This issue affects: Inogard Co,,LTD Ebiz4u ActiveX of Inogard Co,,LTD(AxECM.cab) version 1.0.5.0 and later versions on windows 7/8/10.

    Published: 29 Apr 2020
    6.4
    Medium

    CVE-2020-7804

    Last Modified: 21 Nov 2024

    ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.

    Published: 29 Apr 2020
    7.5
    High

    CVE-2020-2575

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

    Published: 29 Apr 2020
    8.9
    High

    CVE-2020-8773

    Last Modified: 21 Nov 2024

    The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-8774

    Last Modified: 21 Nov 2024

    Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-11677

    Last Modified: 21 Nov 2024

    Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).

    Published: 29 Apr 2020
    7.8
    High

    CVE-2020-12446

    Last Modified: 21 Nov 2024

    The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-11676

    Last Modified: 21 Nov 2024

    Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-11675

    Last Modified: 21 Nov 2024

    Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-11674

    Last Modified: 21 Nov 2024

    Cerner medico 26.00 allows variable reuse, possibly causing data corruption.

    Published: 29 Apr 2020
    4.3
    Medium

    CVE-2019-4288

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160631.

    Published: 29 Apr 2020
    4.3
    Medium

    CVE-2019-4286

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.

    Published: 29 Apr 2020
    6.7
    Medium

    CVE-2017-18856

    Last Modified: 21 Nov 2024

    NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.

    Published: 29 Apr 2020
    7.7
    High

    CVE-2017-18860

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by debugging command execution. This affects FS752TP 5.4.2.19 and earlier, GS108Tv2 5.4.2.29 and earlier, GS110TP 5.4.2.29 and earlier, GS418TPP 6.6.2.6 and earlier, GS510TLP 6.6.2.6 and earlier, GS510TP 5.04.2.27 and earlier, GS510TPP 6.6.2.6 and earlier, GS716Tv2 5.4.2.27 and earlier, GS716Tv3 6.3.1.16 and earlier, GS724Tv3 5.4.2.27 and earlier, GS724Tv4 6.3.1.16 and earlier, GS728TPSB 5.3.0.29 and earlier, GS728TSB 5.3.0.29 and earlier, GS728TXS 6.1.0.35 and earlier, GS748Tv4 5.4.2.27 and earlier, GS748Tv5 6.3.1.16 and earlier, GS752TPSB 5.3.0.29 and earlier, GS752TSB 5.3.0.29 and earlier, GS752TXS 6.1.0.35 and earlier, M4200 12.0.2.10 and earlier, M4300 12.0.2.10 and earlier, M5300 11.0.0.28 and earlier, M6100 11.0.0.28 and earlier, M7100 11.0.0.28 and earlier, S3300 6.6.1.4 and earlier, XS708T 6.6.0.11 and earlier, XS712T 6.1.0.34 and earlier, and XS716T 6.6.0.11 and earlier.

    Published: 29 Apr 2020
    6.1
    Medium

    CVE-2020-10797

    Last Modified: 21 Nov 2024

    An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.

    Published: 29 Apr 2020
    7.8
    High

    CVE-2020-11446

    Last Modified: 21 Nov 2024

    ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2017-18855

    Last Modified: 21 Nov 2024

    NETGEAR WNR854T devices before 1.5.2 are affected by command execution.

    Published: 29 Apr 2020
    6.7
    Medium

    CVE-2017-18854

    Last Modified: 21 Nov 2024

    NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.

    Published: 29 Apr 2020
    6.5
    Medium

    CVE-2017-18853

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by password recovery and file access. This affects D8500 1.0.3.27 and earlier, DGN2200v4 1.0.0.82 and earlier, R6300v2 1.0.4.06 and earlier, R6400 1.0.1.20 and earlier, R6400v2 1.0.2.18 and earlier, R6700 1.0.1.22 and earlier, R6900 1.0.1.20 and earlier, R7000 1.0.7.10 and earlier, R7000P 1.0.0.58 and earlier, R7100LG 1.0.0.28 and earlier, R7300DST 1.0.0.52 and earlier, R7900 1.0.1.12 and earlier, R8000 1.0.3.46 and earlier, R8300 1.0.2.86 and earlier, R8500 1.0.2.86 and earlier, WNDR3400v3 1.0.1.8 and earlier, and WNDR4500v2 1.0.0.62 and earlier.

    Published: 29 Apr 2020
    7.8
    High

    CVE-2019-20781

    Last Modified: 21 Nov 2024

    An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.

    Published: 29 Apr 2020
    6.2
    Medium

    CVE-2020-12252

    Last Modified: 21 Nov 2024

    An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.

    Published: 29 Apr 2020
    2.2
    Low

    CVE-2020-12251

    Last Modified: 21 Nov 2024

    An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an authenticated user to change the filename value (in the POST method) from the original filename to achieve directory traversal via a ../ sequence and, for example, obtain a complete directory listing of the machine.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2019-16653

    Last Modified: 21 Nov 2024

    An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges.

    Published: 29 Apr 2020
    5.4
    Medium

    CVE-2019-7634

    Last Modified: 21 Nov 2024

    SUAP V2 allows XSS during the update of user information.

    Published: 29 Apr 2020
    7.2
    High

    CVE-2019-16652

    Last Modified: 21 Nov 2024

    The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands.

    Published: 29 Apr 2020
    8.8
    High

    CVE-2020-12246

    Last Modified: 21 Nov 2024

    Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.

    Published: 29 Apr 2020
    7.5
    High

    CVE-2020-12447

    Last Modified: 21 Nov 2024

    A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-0000-000-0008-0000 devices allows remote unauthenticated users on the network to read sensitive files via %2e%2e%2f directory traversal, as demonstrated by reading /etc/shadow.

    Published: 29 Apr 2020
    9.3
    Critical

    CVE-2020-3955

    Last Modified: 21 Nov 2024

    ESXi 6.5 without patch ESXi650-201912104-SG and ESXi 6.7 without patch ESXi670-202004103-SG do not properly neutralize script-related HTML when viewing virtual machines attributes. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.3.

    Published: 29 Apr 2020