CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2018-17954

    Last Modified: 21 Nov 2024

    An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue affects: SUSE OpenStack Cloud 7 crowbar-core versions prior to 4.0+git.1578392992.fabfd186c-9.63.1, crowbar-. SUSE OpenStack Cloud 8 ardana-cinder versions prior to 8.0+git.1579279939.ee7da88-3.39.3, ardana-. SUSE OpenStack Cloud 9 ardana-ansible versions prior to 9.0+git.1581611758.f694f7d-3.16.1, ardana-. SUSE OpenStack Cloud Crowbar 8 crowbar-core versions prior to 5.0+git.1582968668.1a55c77c5-3.35.4, crowbar-. SUSE OpenStack Cloud Crowbar 9 crowbar-core versions prior to 6.0+git.1582892022.cbd70e833-3.19.3, crowbar-.

    Published: 3 Apr 2020
    —
    Unknown

    CVE-2019-19914

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Apr 2020
    3.1
    Low

    CVE-2020-5283

    Last Modified: 21 Nov 2024

    ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28.

    Published: 3 Apr 2020
    8.1
    High

    CVE-2020-6820

    Last Modified: 4 Nov 2025

    Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

    Published: 3 Apr 2020
    8.1
    High

    CVE-2020-6819

    Last Modified: 4 Nov 2025

    Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

    Published: 3 Apr 2020
    5.5
    Medium

    CVE-2020-35530

    Last Modified: 21 Nov 2024

    In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggered via a crafted X3F file.

    Published: 3 Apr 2020
    9.8
    Critical

    CVE-2020-11656

    Last Modified: 21 Nov 2024

    In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.

    Published: 3 Apr 2020
    7.5
    High

    CVE-2020-11655

    Last Modified: 21 Nov 2024

    SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

    Published: 3 Apr 2020
    6.1
    Medium

    CVE-2020-11499

    Last Modified: 21 Nov 2024

    Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.

    Published: 2 Apr 2020
    8.8
    High

    CVE-2020-11498

    Last Modified: 21 Nov 2024

    Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistence or to bypass security controls. NOTE: the vendor states that this "requires a high degree of access and other preconditions that are tough to achieve."

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7630

    Last Modified: 21 Nov 2024

    git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7629

    Last Modified: 21 Nov 2024

    install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7628

    Last Modified: 21 Nov 2024

    umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-10515

    Last Modified: 21 Nov 2024

    STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7627

    Last Modified: 21 Nov 2024

    node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7626

    Last Modified: 21 Nov 2024

    karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7625

    Last Modified: 21 Nov 2024

    op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7624

    Last Modified: 21 Nov 2024

    effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7623

    Last Modified: 21 Nov 2024

    jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7621

    Last Modified: 21 Nov 2024

    strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7619

    Last Modified: 21 Nov 2024

    get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-7620

    Last Modified: 21 Nov 2024

    pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.

    Published: 2 Apr 2020
    8
    High

    CVE-2020-9067

    Last Modified: 21 Nov 2024

    There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to perform remote code execution on the affected products when the affected product functions as an optical line terminal (OLT). Affected product versions include:SmartAX MA5600T versions V800R013C10, V800R015C00, V800R015C10, V800R017C00, V800R017C10, V800R018C00, V800R018C10; SmartAX MA5800 versions V100R017C00, V100R017C10, V100R018C00, V100R018C10, V100R019C10; SmartAX EA5800 versions V100R018C00, V100R018C10, V100R019C10.

    Published: 2 Apr 2020
    6.3
    Medium

    CVE-2019-19002

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

    Published: 2 Apr 2020
    6.5
    Medium

    CVE-2019-19001

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.

    Published: 2 Apr 2020
    6.5
    Medium

    CVE-2019-19000

    Last Modified: 21 Nov 2024

    For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

    Published: 2 Apr 2020
    5.9
    Medium

    CVE-2019-19097

    Last Modified: 21 Nov 2024

    ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.

    Published: 2 Apr 2020
    6.1
    Medium

    CVE-2019-19096

    Last Modified: 21 Nov 2024

    The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.

    Published: 2 Apr 2020
    5.4
    Medium

    CVE-2019-19095

    Last Modified: 21 Nov 2024

    Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.

    Published: 2 Apr 2020
    7.6
    High

    CVE-2019-19094

    Last Modified: 21 Nov 2024

    Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.

    Published: 2 Apr 2020
    6.5
    Medium

    CVE-2019-19093

    Last Modified: 21 Nov 2024

    eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

    Published: 2 Apr 2020
    3.5
    Low

    CVE-2019-19092

    Last Modified: 21 Nov 2024

    ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

    Published: 2 Apr 2020
    4.3
    Medium

    CVE-2019-19091

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

    Published: 2 Apr 2020
    3.5
    Low

    CVE-2019-19090

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

    Published: 2 Apr 2020
    6.1
    Medium

    CVE-2019-19089

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.

    Published: 2 Apr 2020
    5.3
    Medium

    CVE-2019-19003

    Last Modified: 21 Nov 2024

    For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.

    Published: 2 Apr 2020
    4.4
    Medium

    CVE-2020-7617

    Last Modified: 21 Nov 2024

    ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.

    Published: 2 Apr 2020
    8.8
    High

    CVE-2020-11107

    Last Modified: 21 Nov 2024

    An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.

    Published: 2 Apr 2020
    8.8
    High

    CVE-2020-11444

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

    Published: 2 Apr 2020
    7.2
    High

    CVE-2020-8423

    Last Modified: 21 Nov 2024

    A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.

    Published: 2 Apr 2020
    6.1
    Medium

    CVE-2019-20635

    Last Modified: 21 Nov 2024

    codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.

    Published: 2 Apr 2020
    5.3
    Medium

    CVE-2020-11453

    Last Modified: 21 Nov 2024

    Microstrategy Web 10.4 is vulnerable to Server-Side Request Forgery in the Test Web Service functionality exposed through the path /MicroStrategyWS/. The functionality requires no authentication and, while it is not possible to pass parameters in the SSRF request, it is still possible to exploit it to conduct port scanning. An attacker could exploit this vulnerability to enumerate the resources allocated in the network (IP addresses and services exposed). NOTE: MicroStrategy is unable to reproduce the issue reported in any version of its product

    Published: 2 Apr 2020
    4.3
    Medium

    CVE-2020-11452

    Last Modified: 21 Nov 2024

    Microstrategy Web 10.4 includes functionality to allow users to import files or data from external resources such as URLs or databases. By providing an external URL under attacker control, it's possible to send requests to external resources (aka SSRF) or leak files from the local system using the file:// stream wrapper.

    Published: 2 Apr 2020
    7.5
    High

    CVE-2020-11450

    Last Modified: 21 Nov 2024

    Microstrategy Web 10.4 exposes the JVM configuration, CPU architecture, installation folder, and other information through the URL /MicroStrategyWS/happyaxis.jsp. An attacker could use this vulnerability to learn more about the environment the application is running in. This issue has been mitigated in all versions of the product 11.0 and higher.

    Published: 2 Apr 2020
    7.2
    High

    CVE-2020-11451

    Last Modified: 21 Nov 2024

    The Upload Visualization plugin in the Microstrategy Web 10.4 admin panel allows an administrator to upload a ZIP archive containing files with arbitrary extensions and data. (This is also exploitable via SSRF). Note: The ability to upload visualization plugins requires administrator privileges.

    Published: 2 Apr 2020
    5.4
    Medium

    CVE-2020-11454

    Last Modified: 21 Nov 2024

    Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, a user needs to get access to a shared dashboard or have the ability to create a dashboard on the application.

    Published: 2 Apr 2020
    7.5
    High

    CVE-2020-9349

    Last Modified: 21 Nov 2024

    The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password.

    Published: 2 Apr 2020
    9.8
    Critical

    CVE-2020-6852

    Last Modified: 21 Nov 2024

    CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.

    Published: 2 Apr 2020
    6.5
    Medium

    CVE-2020-4325

    Last Modified: 21 Nov 2024

    The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine can't recover the memory used by those thread pools, which leads to an OutOfMemory exception when the Process Federation Server Global Teams REST API is used extensively. IBM X-Force ID: 177596.

    Published: 2 Apr 2020
    6.1
    Medium

    CVE-2020-4304

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176670.

    Published: 2 Apr 2020