CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2019-4740

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172808.

    Published: 8 Apr 2020
    5.4
    Medium

    CVE-2019-4737

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172707.

    Published: 8 Apr 2020
    4.3
    Medium

    CVE-2019-4603

    Last Modified: 21 Nov 2024

    IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to create keywords through the REST API and have them appear as if they were created by another user. IBM X-Force ID: 168295.

    Published: 8 Apr 2020
    5.4
    Medium

    CVE-2019-4602

    Last Modified: 21 Nov 2024

    IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168293.

    Published: 8 Apr 2020
    4.3
    Medium

    CVE-2019-4601

    Last Modified: 21 Nov 2024

    IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from a stack trace that could aid in further attacks against the system.

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21089

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has an integer overflow that leads to arbitrary code execution via the download offset control. The Samsung ID is SVE-2017-10732 (January 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21090

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos modem chipset has a baseband buffer overflow. The Samsung ID is SVE-2017-10745 (January 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21091

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnormal exception handling. The Samsung ID is SVE-2017-10906 (January 2018).

    Published: 8 Apr 2020
    6.5
    Medium

    CVE-2018-21092

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2017-18643

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. There is information disclosure of the kbase_context address of a GPU memory node. The Samsung ID is SVE-2017-8907 (December 2017).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2017-18644

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is a muic_set_reg_sel heap-based buffer overflow during the reading of MUIC register values. The Samsung ID is SVE-2017-10011 (December 2017).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2017-18645

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) (Qualcomm chipsets) software. There is a panel_lpm sysfs stack-based buffer overflow. The Samsung ID is SVE-2017-9414 (December 2017).

    Published: 8 Apr 2020
    4.6
    Medium

    CVE-2017-18646

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password requirement for tablet user switching by folding the magnetic cover. The Samsung ID is SVE-2017-10602 (December 2017).

    Published: 8 Apr 2020
    8.8
    High

    CVE-2020-5735

    Last Modified: 31 Oct 2025

    Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to crash the device and possibly execute arbitrary code.

    Published: 8 Apr 2020
    6.5
    Medium

    CVE-2020-5736

    Last Modified: 21 Nov 2024

    Amcrest cameras and NVR are vulnerable to a null pointer dereference over port 37777. An authenticated remote attacker can abuse this issue to crash the device.

    Published: 8 Apr 2020
    8.8
    High

    CVE-2020-5549

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 8 Apr 2020
    8.1
    High

    CVE-2020-5550

    Last Modified: 21 Nov 2024

    Session fixation vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier, and Enterprise Ver. 2.0.1 and earlier allows remote attackers to impersonate a registered user and log in the management console, that may result in information alteration/disclosure via unspecified vectors.

    Published: 8 Apr 2020
    8.8
    High

    CVE-2019-15789

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.

    Published: 8 Apr 2020
    6.1
    Medium

    CVE-2020-10633

    Last Modified: 21 Nov 2024

    A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

    Published: 8 Apr 2020
    7.5
    High

    CVE-2020-6821

    Last Modified: 21 Nov 2024

    When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

    Published: 8 Apr 2020
    8.8
    High

    CVE-2020-6822

    Last Modified: 21 Nov 2024

    On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2020-6825

    Last Modified: 21 Nov 2024

    Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.

    Published: 8 Apr 2020
    5.5
    Medium

    CVE-2020-35533

    Last Modified: 21 Nov 2024

    In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.

    Published: 8 Apr 2020
    4.7
    Medium

    CVE-2020-6827

    Last Modified: 21 Nov 2024

    When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

    Published: 8 Apr 2020
    7.5
    High

    CVE-2020-6828

    Last Modified: 21 Nov 2024

    A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient compromise such that it is generally equivalent to arbitrary code execution.<br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

    Published: 8 Apr 2020
    7.5
    High

    CVE-2020-10366

    Last Modified: 21 Nov 2024

    LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-11626

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-11627

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.

    Published: 7 Apr 2020
    5.3
    Medium

    CVE-2020-11628

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the system configuration. These restrictions can be bypassed by modifying the URI string from a client. (EJBCA's internal access control restrictions are still in place, and each respective protocol must be configured to allow for enrollment.)

    Published: 7 Apr 2020
    7.2
    High

    CVE-2020-11629

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save uploaded test certificates to the server. An attacker who has gained access to the CA UI could exploit this to upload malicious scripts to the server. (Risks associated with this issue alone are negligible unless a malicious user already has gained access to the CA UI through other means, as a trusted user is already trusted to upload scripts by virtue of having access to the validator.)

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-11630

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-11631

    Last Modified: 21 Nov 2024

    An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of other bugs. This follow-on exploitation can lead to privilege escalation and remote code execution. (This is exploitable only when at least one accessible port lacks a requirement for client certificate authentication. These ports are 8442 or 8080 in a standard installation.)

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-11543

    Last Modified: 21 Nov 2024

    OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user accounts for the gateway appliance.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-9286

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-11509

    Last Modified: 21 Nov 2024

    An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-11508

    Last Modified: 21 Nov 2024

    An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-6647

    Last Modified: 21 Nov 2024

    An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.

    Published: 7 Apr 2020
    7.1
    High

    CVE-2015-9544

    Last Modified: 21 Nov 2024

    An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-11610

    Last Modified: 21 Nov 2024

    An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-11611

    Last Modified: 21 Nov 2024

    An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain that is currently loaded within the iframe can receive the messages that the client sends.

    Published: 7 Apr 2020
    7.1
    High

    CVE-2015-9545

    Last Modified: 21 Nov 2024

    An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can entice a user to load a malicious site can exploit this issue to impact the confidentiality and integrity of data in the local storage of the vulnerable site via malicious web messages.

    Published: 7 Apr 2020
    7.5
    High

    CVE-2019-17657

    Last Modified: 21 Nov 2024

    An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-6974

    Last Modified: 21 Nov 2024

    Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

    Published: 7 Apr 2020
    7.8
    High

    CVE-2019-13559

    Last Modified: 21 Nov 2024

    GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instructions immediately available to the end user. The bulk of controllers go into applications requiring the GE commissioning engineer to change default configurations during the installation process. GE recommends that users reset controller passwords during installation in the operating environment.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2019-13554

    Last Modified: 21 Nov 2024

    GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credentials. GE recommends that users disable the Telnet service.

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-11516

    Last Modified: 21 Nov 2024

    Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a contact form, the JavaScript will be executed in their browser, which can then be used to create new administrative users or perform other actions using the administrator's session.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-11515

    Last Modified: 21 Nov 2024

    The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-11514

    Last Modified: 21 Nov 2024

    The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-9514

    Last Modified: 21 Nov 2024

    An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbitrary posts and pages, create new posts with arbitrary subjects, and modify the subjects of existing posts and pages (via create_dynamic_page and delete_dynamic_page).

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-11512

    Last Modified: 21 Nov 2024

    Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subscriber-level) permissions to save arbitrary JavaScript in the plugin's settings panel via the idx_update_recaptcha_key AJAX action and a crafted idx_recaptcha_site_key parameter, which would then be executed in the browser of any administrator visiting the panel. This could be used to create new administrator-level accounts.

    Published: 7 Apr 2020