CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-20653

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by denial of service. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

    Published: 15 Apr 2020
    6.5
    Medium

    CVE-2019-20652

    Last Modified: 21 Nov 2024

    NETGEAR WAC505 devices before 8.2.1.16 are affected by disclosure of sensitive information.

    Published: 15 Apr 2020
    6.7
    Medium

    CVE-2019-20651

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 8.2.1.16 and WAC510 before 8.2.1.16.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2020-10611

    Last Modified: 21 Nov 2024

    Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authentication is not required to exploit this vulnerability. Only applicable to installations using DNP3 Data Sets.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2019-12524

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via url_regex. The handler for url_regex rules URL decodes an incoming request. This allows an attacker to encode their URL to bypass the url_regex check, and gain access to the blocked resource.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2020-10613

    Last Modified: 21 Nov 2024

    Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. Authentication is not required to exploit this vulnerability. Only applicable to installations using DNP3 Data Sets.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2020-10615

    Last Modified: 21 Nov 2024

    Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based buffer. Authentication is not required to exploit this vulnerability.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2020-11799

    Last Modified: 21 Nov 2024

    Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in a location that other unprivileged users have access to.

    Published: 15 Apr 2020
    7.9
    High

    CVE-2020-5350

    Last Modified: 21 Nov 2024

    Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-5346

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.4 P11 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2019-20650

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR500 before 2.3.2.56, and XR700 before 1.0.1.20.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2019-20649

    Last Modified: 21 Nov 2024

    NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.

    Published: 15 Apr 2020
    3.5
    Low

    CVE-2019-20648

    Last Modified: 21 Nov 2024

    NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.

    Published: 15 Apr 2020
    5.7
    Medium

    CVE-2019-20647

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.64 are affected by denial of service.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2019-20646

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of administrative credentials.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-3953

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2019-20645

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2019-20644

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.

    Published: 15 Apr 2020
    6.1
    Medium

    CVE-2020-3954

    Last Modified: 21 Nov 2024

    Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2019-20643

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.

    Published: 15 Apr 2020
    8
    High

    CVE-2019-20642

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.

    Published: 15 Apr 2020
    8.8
    High

    CVE-2019-20641

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.

    Published: 15 Apr 2020
    8.8
    High

    CVE-2019-20640

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2019-20639

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

    Published: 15 Apr 2020
    6.5
    Medium

    CVE-2019-20638

    Last Modified: 21 Nov 2024

    NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2020-11792

    Last Modified: 21 Nov 2024

    NETGEAR R8900, R9000, RAX120, and XR700 devices before 2020-01-20 are affected by Transport Layer Security (TLS) certificate private key disclosure.

    Published: 15 Apr 2020
    6.1
    Medium

    CVE-2020-11791

    Last Modified: 21 Nov 2024

    NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2020-11790

    Last Modified: 21 Nov 2024

    NETGEAR R7800 devices before 1.0.2.68 are affected by remote code execution by unauthenticated attackers.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2020-11789

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

    Published: 15 Apr 2020
    8.8
    High

    CVE-2020-11788

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.34, D7000 before 1.0.1.68, PR2000 before 1.0.0.28, R6050 before 1.0.1.18, JR6150 before 1.0.1.18, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6260 before 1.1.0.64, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, and R6900v2 before 1.2.0.36.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-11787

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-11786

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-0600

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in firmware for some Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-0598

    Last Modified: 21 Nov 2024

    Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 15 Apr 2020
    8.8
    High

    CVE-2020-0577

    Last Modified: 21 Nov 2024

    Insufficient control flow for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 15 Apr 2020
    6.5
    Medium

    CVE-2020-0576

    Last Modified: 21 Nov 2024

    Buffer overflow in Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 15 Apr 2020
    8.8
    High

    CVE-2020-0578

    Last Modified: 21 Nov 2024

    Improper conditions check for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 15 Apr 2020
    4.7
    Medium

    CVE-2020-0568

    Last Modified: 21 Nov 2024

    Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 15 Apr 2020
    6.5
    Medium

    CVE-2020-0558

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in kernel mode driver for Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an unprivileged user to potentially enable denial of service via adjacent access.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-0557

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-0547

    Last Modified: 21 Nov 2024

    Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-10639

    Last Modified: 21 Nov 2024

    Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could cause a buffer overflow when loaded by the affected product.

    Published: 15 Apr 2020
    5.5
    Medium

    CVE-2020-10637

    Last Modified: 21 Nov 2024

    Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially crafted input file could trigger an out-of-bounds read when loaded by the affected product.

    Published: 15 Apr 2020
    6.7
    Medium

    CVE-2020-6992

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vulnerability could allow an adversary to modify the system, leading to the arbitrary execution of code. This vulnerability is only exploitable if an attacker has access to an authenticated session. GE Digital CIMPLICITY v11.0, released January 2020, contains mitigation for this local privilege escalation vulnerability. GE Digital recommends all users upgrade to GE CIMPLICITY v11.0 or newer.

    Published: 15 Apr 2020
    5.4
    Medium

    CVE-2019-19390

    Last Modified: 21 Nov 2024

    The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-11785

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

    Published: 15 Apr 2020
    4.8
    Medium

    CVE-2020-11784

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, RBK50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

    Published: 15 Apr 2020
    7.5
    High

    CVE-2020-11728

    Last Modified: 21 Nov 2024

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.

    Published: 15 Apr 2020
    9.8
    Critical

    CVE-2020-11729

    Last Modified: 21 Nov 2024

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.

    Published: 15 Apr 2020
    7.8
    High

    CVE-2020-8948

    Last Modified: 21 Nov 2024

    The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.

    Published: 15 Apr 2020