CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-10863

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine.

    Published: 1 Apr 2020
    7.8
    High

    CVE-2020-10862

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Local Privilege Escalation (LPE) via RPC.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10861

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to achieve Arbitrary File Deletion from Avast Program Path via RPC, when Self Defense is Enabled.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10860

    Last Modified: 21 Nov 2024

    An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe).

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2018-11106

    Last Modified: 21 Nov 2024

    NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2019-3944

    Last Modified: 21 Nov 2024

    Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2019-3945

    Last Modified: 21 Nov 2024

    Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control service with larger than expected date length.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2019-3942

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-11455

    Last Modified: 21 Nov 2024

    LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

    Published: 1 Apr 2020
    5.4
    Medium

    CVE-2020-11456

    Last Modified: 21 Nov 2024

    LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).

    Published: 1 Apr 2020
    5.4
    Medium

    CVE-2020-11457

    Last Modified: 21 Nov 2024

    pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-11449

    Last Modified: 21 Nov 2024

    An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-10231

    Last Modified: 21 Nov 2024

    TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-7948

    Last Modified: 21 Nov 2024

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference.

    Published: 1 Apr 2020
    9.8
    Critical

    CVE-2020-7947

    Last Modified: 21 Nov 2024

    An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.

    Published: 1 Apr 2020
    8.8
    High

    CVE-2020-5391

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-6753

    Last Modified: 21 Nov 2024

    The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-5392

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-5548

    Last Modified: 21 Nov 2024

    Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and earlier, RTX830 firmware Rev.15.02.09 and earlier, RTX1200 firmware Rev.10.01.76 and earlier, RTX1210 firmware Rev.14.01.33 and earlier, RTX3500 firmware Rev.14.00.26 and earlier, and RTX5000 firmware Rev.14.00.26 and earlier), Yamaha Broadband VoIP Router(NVR500 firmware Rev.11.00.38 and earlier), and Yamaha Firewall(FWX120 firmware Rev.11.03.27 and earlier) allow remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-7263

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-11445

    Last Modified: 21 Nov 2024

    TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.

    Published: 1 Apr 2020
    5.4
    Medium

    CVE-2020-11110

    Last Modified: 21 Nov 2024

    Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

    Published: 1 Apr 2020
    4.4
    Medium

    CVE-2020-11494

    Last Modified: 21 Nov 2024

    An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.

    Published: 1 Apr 2020
    6.1
    Medium

    CVE-2020-1927

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-1934

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-1954

    Last Modified: 21 Nov 2024

    Apache CXF has the ability to integrate with JMX by registering an InstrumentationManager extension with the CXF bus. If the ‘createMBServerConnectorFactory‘ property of the default InstrumentationManagerImpl is not disabled, then it is vulnerable to a man-in-the-middle (MITM) style attack. An attacker on the same host can connect to the registry and rebind the entry to another server, thus acting as a proxy to the original. They are then able to gain access to all of the information that is sent and received over JMX.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-1958

    Last Modified: 21 Nov 2024

    When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.

    Published: 1 Apr 2020
    5.3
    Medium

    CVE-2020-7066

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may cause some software to make incorrect assumptions about the target of the get_headers() and possibly send some information to a wrong server.

    Published: 1 Apr 2020
    6
    Medium

    CVE-2020-11565

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community disagrees that this is a vulnerability because the issue “is a bug in parsing mount options which can only be specified by a privileged user, so triggering the bug does not grant any powers not already held.”

    Published: 1 Apr 2020
    7.5
    High

    CVE-2020-11647

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

    Published: 1 Apr 2020
    6.5
    Medium

    CVE-2020-7064

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.

    Published: 1 Apr 2020
    8.1
    High

    CVE-2020-7660

    Last Modified: 21 Nov 2024

    serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

    Published: 1 Apr 2020
    7.4
    High

    CVE-2020-7065

    Last Modified: 21 Nov 2024

    In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.

    Published: 1 Apr 2020
    7
    High

    CVE-2020-5344

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

    Published: 31 Mar 2020
    8.7
    High

    CVE-2020-5292

    Last Modified: 21 Nov 2024

    Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like the users' and administrators' password hashes, modify data, or drop tables. The unescaped parameter is "searchUsers" when sending a POST request to "/tickets/showKanban" with a valid session. In the code, the parameter is named "users" in class.tickets.php. This issue is fixed in versions 2.0.15 and 2.1.0 beta 3.

    Published: 31 Mar 2020
    5.4
    Medium

    CVE-2019-13495

    Last Modified: 21 Nov 2024

    In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenticated users to inject arbitrary web script via an rpSys.html Name or Location field.

    Published: 31 Mar 2020
    6.1
    Medium

    CVE-2020-11441

    Last Modified: 21 Nov 2024

    phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

    Published: 31 Mar 2020
    9.1
    Critical

    CVE-2019-14880

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-4242

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-4241

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.

    Published: 31 Mar 2020
    6.5
    Medium

    CVE-2020-4240

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to overwrite or create arbitrary files on the system. IBM X-Force ID: 175417.

    Published: 31 Mar 2020
    5.3
    Medium

    CVE-2020-4239

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 175412.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-4238

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-4237

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.

    Published: 31 Mar 2020
    6.5
    Medium

    CVE-2020-4236

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 could allow an authenticated user to cause a denial of service due to improper content parsing in the project management module. IBM X-Force ID: 175409.

    Published: 31 Mar 2020
    5.4
    Medium

    CVE-2020-4235

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175408.

    Published: 31 Mar 2020
    7.5
    High

    CVE-2020-4214

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.

    Published: 31 Mar 2020
    9.8
    Critical

    CVE-2020-4208

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-4206

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary commands on the system in the context of root user, caused by improper validation of user-supplied input. IBM X-Force ID: 174966.

    Published: 31 Mar 2020
    9.8
    Critical

    CVE-2020-6008

    Last Modified: 21 Nov 2024

    LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

    Published: 31 Mar 2020