CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-4303

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 20.0.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176668.

    Published: 2 Apr 2020
    6.2
    Medium

    CVE-2020-8017

    Last Modified: 21 Nov 2024

    A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in group mktex to delete arbitrary files on the system This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.

    Published: 2 Apr 2020
    4.9
    Medium

    CVE-2020-8016

    Last Modified: 21 Nov 2024

    A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users to corrupt files or potentially escalate privileges. This issue affects: SUSE Linux Enterprise Module for Desktop Applications 15-SP1 texlive-filesystem versions prior to 2017.135-9.5.1. SUSE Linux Enterprise Software Development Kit 12-SP4 texlive-filesystem versions prior to 2013.74-16.5.1. SUSE Linux Enterprise Software Development Kit 12-SP5 texlive-filesystem versions prior to 2013.74-16.5.1. openSUSE Leap 15.1 texlive-filesystem versions prior to 2017.135-lp151.8.3.1.

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-6999

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7009

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7010

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7011

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7012

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7013

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7016

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    —
    Unknown

    CVE-2019-7017

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 2 Apr 2020
    8.8
    High

    CVE-2018-13371

    Last Modified: 21 Nov 2024

    An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.

    Published: 2 Apr 2020
    7.2
    High

    CVE-2020-11490

    Last Modified: 21 Nov 2024

    Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.

    Published: 2 Apr 2020
    4.9
    Medium

    CVE-2020-11491

    Last Modified: 21 Nov 2024

    Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attacks, as demonstrated by a filelog=/etc/shadow request to index.cgi.

    Published: 2 Apr 2020
    8.8
    High

    CVE-2020-11100

    Last Modified: 21 Nov 2024

    In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.

    Published: 2 Apr 2020
    4.9
    Medium

    CVE-2020-11458

    Last Modified: 21 Nov 2024

    app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are passwords from database.php or GPG key passphrases from config.php.

    Published: 2 Apr 2020
    5.5
    Medium

    CVE-2020-35532

    Last Modified: 21 Nov 2024

    In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

    Published: 2 Apr 2020
    5.5
    Medium

    CVE-2020-10702

    Last Modified: 21 Nov 2024

    A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.

    Published: 2 Apr 2020
    7.5
    High

    CVE-2020-13164

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.

    Published: 2 Apr 2020
    5.5
    Medium

    CVE-2020-35531

    Last Modified: 21 Nov 2024

    In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

    Published: 2 Apr 2020
    7.5
    High

    CVE-2020-1983

    Last Modified: 21 Nov 2024

    A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

    Published: 2 Apr 2020
    7.8
    High

    CVE-2020-8146

    Last Modified: 21 Nov 2024

    In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the controller is running on Windows and adjusting the SafeDllSearchMode in the windows registry when installing UniFi-Video controller. Affected Products: UniFi Video Controller v3.10.2 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.10.3 and newer.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-8145

    Last Modified: 21 Nov 2024

    The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.

    Published: 1 Apr 2020
    8.4
    High

    CVE-2020-8144

    Last Modified: 21 Nov 2024

    The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It accepts a request with a URL to firmware update information. If the version field contains ..\ character sequences, the destination file path to save the firmware can be manipulated to be outside the intended destination directory tree. Fixed in UniFi Video Controller v3.10.3 and newer.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-11469

    Last Modified: 21 Nov 2024

    Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.

    Published: 1 Apr 2020
    3.3
    Low

    CVE-2020-11470

    Last Modified: 21 Nov 2024

    Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2019-17564

    Last Modified: 21 Nov 2024

    Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-6009

    Last Modified: 21 Nov 2024

    LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-10598

    Last Modified: 21 Nov 2024

    In BD Pyxis MedStation ES System v1.6.1 and Pyxis Anesthesia (PAS) ES System v1.6.1, a restricted desktop environment escape vulnerability exists in the kiosk mode functionality of affected devices. Specially crafted inputs could allow the user to escape the restricted environment, resulting in access to sensitive data.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-11463

    Last Modified: 21 Nov 2024

    An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-11464

    Last Modified: 21 Nov 2024

    An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address, phone number, etc.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-11465

    Last Modified: 21 Nov 2024

    An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

    Published: 1 Apr 2020
    4.3
    Medium

    CVE-2020-11466

    Last Modified: 21 Nov 2024

    An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket.

    Published: 1 Apr 2020
    7.2
    High

    CVE-2020-11467

    Last Modified: 21 Nov 2024

    An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. While direct access to self and _self variables was not permitted, one could abuse the accessible variables in one's context to reach a native unserialize function via the code parameter. There, on could pass a crafted payload to trigger a set of POP gadgets in order to achieve remote code execution.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2019-9163

    Last Modified: 21 Nov 2024

    The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-8966

    Last Modified: 21 Nov 2024

    There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-10948

    Last Modified: 21 Nov 2024

    Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-5290

    Last Modified: 21 Nov 2024

    In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by, for example, exploiting a stored XSS payload in a CTF challenge so that victim teams who solve the challenge are unknowingly (and against their will) signed into the attacker team's account. Then, the attacker can gain points / value off the backs of the victims. This is patched in version 2.3.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-10199

    Last Modified: 7 Nov 2025

    Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-1949

    Last Modified: 21 Nov 2024

    Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.

    Published: 1 Apr 2020
    7.2
    High

    CVE-2020-10204

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-1943

    Last Modified: 21 Nov 2024

    Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3847

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3849

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3848

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-3850

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

    Published: 1 Apr 2020
    4.8
    Medium

    CVE-2020-10203

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository before 3.21.2 allows XSS.

    Published: 1 Apr 2020