CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-11544

    Last Modified: 21 Nov 2024

    An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-11545

    Last Modified: 21 Nov 2024

    Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.

    Published: 6 Apr 2020
    6.6
    Medium

    CVE-2020-9473

    Last Modified: 21 Nov 2024

    The S. Siedle & Soehne SG 150-0 Smart Gateway before 1.2.4 has a passwordless ftp ssh user. By using an exploit chain, an attacker with access to the network can get root access on the gateway.

    Published: 6 Apr 2020
    6.5
    Medium

    CVE-2020-7622

    Last Modified: 21 Nov 2024

    This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-7639

    Last Modified: 21 Nov 2024

    eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-8004

    Last Modified: 21 Nov 2024

    STMicroelectronics STM32F1 devices have Incorrect Access Control.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-7638

    Last Modified: 21 Nov 2024

    confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.

    Published: 6 Apr 2020
    5.3
    Medium

    CVE-2020-7637

    Last Modified: 21 Nov 2024

    class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7636

    Last Modified: 21 Nov 2024

    adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7635

    Last Modified: 21 Nov 2024

    compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7634

    Last Modified: 21 Nov 2024

    heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7633

    Last Modified: 21 Nov 2024

    apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7632

    Last Modified: 21 Nov 2024

    node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-7631

    Last Modified: 21 Nov 2024

    diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.

    Published: 6 Apr 2020
    7.5
    High

    CVE-2020-10267

    Last Modified: 21 Nov 2024

    Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps) are stored under '/root/.urcaps' as plain zip files containing all the logic to add functionality to the UR3, UR5 and UR10 robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property.

    Published: 6 Apr 2020
    8.1
    High

    CVE-2020-10266

    Last Modified: 21 Nov 2024

    UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When installing any of these components in the robots (e.g. in the UR10), no integrity checks are performed. Moreover, the SDK for making such components can be easily obtained from Universal Robots. An attacker could exploit this flaw by crafting a custom component with the SDK, performing Person-In-The-Middle attacks (PITM) and shipping the maliciously-crafted component on demand.

    Published: 6 Apr 2020
    9.4
    Critical

    CVE-2020-10265

    Last Modified: 21 Nov 2024

    Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.

    Published: 6 Apr 2020
    8.8
    High

    CVE-2020-10264

    Last Modified: 21 Nov 2024

    CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog Outputs. Additionally unautheticated reading of robot data is also possible

    Published: 6 Apr 2020
    8.1
    High

    CVE-2020-11619

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).

    Published: 6 Apr 2020
    9.8
    Critical

    CVE-2020-11558

    Last Modified: 21 Nov 2024

    An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.

    Published: 5 Apr 2020
    5.5
    Medium

    CVE-2020-14150

    Last Modified: 21 Nov 2024

    GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison itself, not that a crash may occur in code that is generated by Bison.

    Published: 5 Apr 2020
    9.8
    Critical

    CVE-2020-11548

    Last Modified: 21 Nov 2024

    The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

    Published: 4 Apr 2020
    5.3
    Medium

    CVE-2020-11547

    Last Modified: 21 Nov 2024

    PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

    Published: 4 Apr 2020
    9.8
    Critical

    CVE-2020-11542

    Last Modified: 21 Nov 2024

    3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.

    Published: 4 Apr 2020
    5.5
    Medium

    CVE-2020-11533

    Last Modified: 21 Nov 2024

    Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).

    Published: 4 Apr 2020
    6.1
    Medium

    CVE-2020-11529

    Last Modified: 21 Nov 2024

    Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

    Published: 4 Apr 2020
    7.5
    High

    CVE-2020-11528

    Last Modified: 21 Nov 2024

    bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.

    Published: 4 Apr 2020
    7.5
    High

    CVE-2020-11527

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.

    Published: 4 Apr 2020
    9.8
    Critical

    CVE-2020-11518

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.

    Published: 4 Apr 2020
    6.7
    Medium

    CVE-2019-20636

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.

    Published: 4 Apr 2020
    6.8
    Medium

    CVE-2020-5348

    Last Modified: 21 Nov 2024

    Dell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A local unauthenticated attacker may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in system management mode.

    Published: 3 Apr 2020
    5.3
    Medium

    CVE-2020-5347

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions 8.2.2 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.

    Published: 3 Apr 2020
    6.1
    Medium

    CVE-2020-8143

    Last Modified: 21 Nov 2024

    An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-8147

    Last Modified: 21 Nov 2024

    Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.

    Published: 3 Apr 2020
    6.8
    Medium

    CVE-2020-8142

    Last Modified: 21 Nov 2024

    A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change the e-mail address or the password. It was however possible for anyone with access to a Revive Adserver admin user interface to bypass such check and change e-email address or password of the currently logged in user by altering the form payload.The attack requires physical access to the user interface of a logged in user. If the POST payload was altered by turning the “pwold” parameter into an array, Revive Adserver would fetch and authorise the operation even if no password was provided.

    Published: 3 Apr 2020
    8.8
    High

    CVE-2020-8639

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-8638

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-8637

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-6994

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-10599

    Last Modified: 21 Nov 2024

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.

    Published: 3 Apr 2020
    7.5
    High

    CVE-2020-7000

    Last Modified: 21 Nov 2024

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow an unauthenticated attacker to discover the cryptographic key from the web server and gain information about the login and the encryption/decryption mechanism, which may be exploited to bypass authentication of the HTML5 HMI web interface.

    Published: 3 Apr 2020
    7.8
    High

    CVE-2020-10601

    Last Modified: 21 Nov 2024

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module allow weak hashing algorithm and insecure permissions which may allow a local attacker to bypass the password-protected mechanism through brute-force attacks, cracking techniques, or overwriting the password hash.

    Published: 3 Apr 2020
    8.8
    High

    CVE-2020-7004

    Last Modified: 21 Nov 2024

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.

    Published: 3 Apr 2020
    7.5
    High

    CVE-2020-7008

    Last Modified: 21 Nov 2024

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.

    Published: 3 Apr 2020
    5.3
    Medium

    CVE-2019-17230

    Last Modified: 21 Nov 2024

    includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.

    Published: 3 Apr 2020
    6.1
    Medium

    CVE-2019-17231

    Last Modified: 21 Nov 2024

    includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.

    Published: 3 Apr 2020
    7.8
    High

    CVE-2020-4273

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 4.2 and 5.0 could allow a local unprivileged attacker with intimate knowledge of the enviornment to execute commands as root using specially crafted input. IBM X-Force ID: 175977.

    Published: 3 Apr 2020
    7.5
    High

    CVE-2020-11500

    Last Modified: 21 Nov 2024

    Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.

    Published: 3 Apr 2020
    4.8
    Medium

    CVE-2019-18905

    Last Modified: 21 Nov 2024

    A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows remote attackers to MITM connections when deprecated and unused functionality of autoyast is used to create images. This issue affects: SUSE Linux Enterprise Server 12 autoyast2 version 4.1.9-3.9.1 and prior versions. SUSE Linux Enterprise Server 15 autoyast2 version 4.0.70-3.20.1 and prior versions.

    Published: 3 Apr 2020
    6.5
    Medium

    CVE-2019-18904

    Last Modified: 21 Nov 2024

    A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15-SP1, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1 allows remote attackers to cause DoS against rmt by requesting migrations. This issue affects: SUSE Linux Enterprise High Performance Computing 15-ESPOS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise High Performance Computing 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Public Cloud 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Module for Server Applications 15 rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Module for Server Applications 15-SP1 rmt-server versions prior to 2.5.2-3.9.1. SUSE Linux Enterprise Server 15-LTSS rmt-server versions prior to 2.5.2-3.26.1. SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.5.2-3.26.1. openSUSE Leap 15.1 rmt-server versions prior to 2.5.2-lp151.2.9.1.

    Published: 3 Apr 2020