CVE Feed

    Dashboard / CVE

    4.2
    Medium

    CVE-2019-2391

    Last Modified: 23 Feb 2026

    Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.

    Published: 31 Mar 2020
    7.5
    High

    CVE-2020-11414

    Last Modified: 21 Nov 2024

    An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.

    Published: 31 Mar 2020
    9.8
    Critical

    CVE-2020-10595

    Last Modified: 21 Nov 2024

    pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacker responds to a prompt with an answer of a carefully chosen length. The effect may range from heap corruption to stack corruption depending on the structure of the underlying Kerberos library, with unknown effects but possibly including code execution. This code path is not used for normal authentication, but only when the Kerberos library does supplemental prompting, such as with PKINIT or when using the non-standard no_prompt PAM configuration option.

    Published: 31 Mar 2020
    5.3
    Medium

    CVE-2020-10933

    Last Modified: 21 Nov 2024

    An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.

    Published: 31 Mar 2020
    5.5
    Medium

    CVE-2020-11042

    Last Modified: 21 Nov 2024

    In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-6451

    Last Modified: 21 Nov 2024

    Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-6453

    Last Modified: 21 Nov 2024

    Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-7009

    Last Modified: 21 Nov 2024

    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can perform a series of steps that result in an API key being generated with elevated privileges.

    Published: 31 Mar 2020
    7.2
    High

    CVE-2020-5291

    Last Modified: 21 Nov 2024

    Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects the combination of bubblewrap in setuid mode (which is typically used when unprivileged user namespaces are not supported) and the support of unprivileged user namespaces. Known to be affected are: * Debian testing/unstable, if unprivileged user namespaces enabled (not default) * Debian buster-backports, if unprivileged user namespaces enabled (not default) * Arch if using `linux-hardened`, if unprivileged user namespaces enabled (not default) * Centos 7 flatpak COPR, if unprivileged user namespaces enabled (not default) This has been fixed in the 0.4.1 release, and all affected users should update.

    Published: 31 Mar 2020
    2.2
    Low

    CVE-2020-11044

    Last Modified: 21 Nov 2024

    In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-6452

    Last Modified: 21 Nov 2024

    Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 31 Mar 2020
    8.8
    High

    CVE-2020-6450

    Last Modified: 21 Nov 2024

    Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 31 Mar 2020
    9.8
    Critical

    CVE-2020-7611

    Last Modified: 21 Nov 2024

    All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.

    Published: 30 Mar 2020
    6.1
    Medium

    CVE-2020-11106

    Last Modified: 21 Nov 2024

    An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then returns to the dialog.php page. This occurs because ajax_calls.php was also able to set the $_SESSION['RF']["view_type"] variable, but there it wasn't sanitized.

    Published: 30 Mar 2020
    9.8
    Critical

    CVE-2019-19605

    Last Modified: 21 Nov 2024

    X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution.

    Published: 30 Mar 2020
    9.8
    Critical

    CVE-2019-19606

    Last Modified: 21 Nov 2024

    X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.

    Published: 30 Mar 2020
    5.3
    Medium

    CVE-2020-11104

    Last Modified: 21 Nov 2024

    An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several bytes of stack or heap memory, from which sensitive information (such as memory layout or private keys) can be gleaned if the archive is distributed outside of a trusted context.

    Published: 30 Mar 2020
    9.8
    Critical

    CVE-2020-11105

    Last Modified: 21 Nov 2024

    An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is freed, and a new std::shared_ptr is allocated at the same address. Serialization fidelity thereby becomes dependent upon memory layout. In short, serialized std::shared_ptr variables cannot always be expected to serialize back into their original values. This can have any number of consequences, depending on the context within which this manifests.

    Published: 30 Mar 2020
    4.8
    Medium

    CVE-2019-19912

    Last Modified: 21 Nov 2024

    In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature allows authenticated remote attackers to inject arbitrary scripts via an active script embedded in an SWF file.

    Published: 30 Mar 2020
    4.8
    Medium

    CVE-2019-19913

    Last Modified: 21 Nov 2024

    In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.

    Published: 30 Mar 2020
    6.8
    Medium

    CVE-2020-5289

    Last Modified: 21 Nov 2024

    In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field in the model. The adversary can construct filter expressions for an inaccessible field to filter a collection. The presence or absence of models in the returned collection can be used to reconstruct the value of the inaccessible field. Resolved in Elide 4.5.14 and greater.

    Published: 30 Mar 2020
    9.8
    Critical

    CVE-2020-10374

    Last Modified: 21 Nov 2024

    A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.

    Published: 30 Mar 2020
    3.7
    Low

    CVE-2019-20634

    Last Modified: 21 Nov 2024

    An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.

    Published: 30 Mar 2020
    3.9
    Low

    CVE-2020-9055

    Last Modified: 21 Nov 2024

    Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.

    Published: 30 Mar 2020
    6.3
    Medium

    CVE-2019-9509

    Last Modified: 21 Nov 2024

    The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST parameter. The web application does not neutralize user-controllable input before displaying to users in a web page, which could allow a remote attacker authenticated with a user account to execute arbitrary code.

    Published: 30 Mar 2020
    6.3
    Medium

    CVE-2019-9508

    Last Modified: 21 Nov 2024

    The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application that would execute each time a user browsed to the page.

    Published: 30 Mar 2020
    8.3
    High

    CVE-2019-9507

    Last Modified: 21 Nov 2024

    The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed as root, this could allow a remote attacker authenticated with an administrator account to execute arbitrary commands as root.

    Published: 30 Mar 2020
    4.4
    Medium

    CVE-2020-5284

    Last Modified: 21 Nov 2024

    Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

    Published: 30 Mar 2020
    7.6
    High

    CVE-2020-5275

    Last Modified: 21 Nov 2024

    In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute. This issue is patched in versions 4.4.7 and 5.0.7.

    Published: 30 Mar 2020
    4.6
    Medium

    CVE-2020-5274

    Last Modified: 21 Nov 2024

    In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

    Published: 30 Mar 2020
    2.6
    Low

    CVE-2020-5255

    Last Modified: 21 Nov 2024

    In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

    Published: 30 Mar 2020
    7.5
    High

    CVE-2020-5726

    Last Modified: 21 Nov 2024

    The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

    Published: 30 Mar 2020
    5.9
    Medium

    CVE-2020-5725

    Last Modified: 21 Nov 2024

    The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.

    Published: 30 Mar 2020
    7.5
    High

    CVE-2020-5724

    Last Modified: 21 Nov 2024

    The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

    Published: 30 Mar 2020
    9.8
    Critical

    CVE-2020-5723

    Last Modified: 21 Nov 2024

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

    Published: 30 Mar 2020
    7.5
    High

    CVE-2019-17561

    Last Modified: 21 Nov 2024

    The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

    Published: 30 Mar 2020
    9.1
    Critical

    CVE-2019-17560

    Last Modified: 21 Nov 2024

    The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

    Published: 30 Mar 2020
    6.5
    Medium

    CVE-2020-7599

    Last Modified: 21 Nov 2024

    All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with the --info log level flag, the Gradle Logger logs an AWS pre-signed URL. If this build log is publicly visible (as it is in many popular public CI systems like TravisCI) this AWS pre-signed URL would allow a malicious actor to replace a recently uploaded plugin with their own.

    Published: 30 Mar 2020
    7.5
    High

    CVE-2020-8509

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.

    Published: 30 Mar 2020
    8.8
    High

    CVE-2019-7755

    Last Modified: 21 Nov 2024

    In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

    Published: 30 Mar 2020
    7.8
    High

    CVE-2020-8835

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)

    Published: 30 Mar 2020
    5.9
    Medium

    CVE-2020-10560

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert into a crafted URL for components/OssnComments/ossn_com.php and/or libraries/ossn.lib.upgrade.php.

    Published: 30 Mar 2020
    7.5
    High

    CVE-2020-5527

    Last Modified: 21 Nov 2024

    When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly. As a result, it may fall into a denial-of-service (DoS) condition. The vendor states this vulnerability only affects Ethernet communication functions.

    Published: 30 Mar 2020
    8.8
    High

    CVE-2020-5551

    Last Modified: 21 Nov 2024

    Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the regions other than Japan from Oct. 2016 to Oct. 2019. An attacker with certain knowledge on the target vehicle control system may be able to send some diagnostic commands to ECUs with some limited availability impacts; the vendor states critical vehicle controls such as driving, turning, and stopping are not affected.

    Published: 30 Mar 2020
    5.5
    Medium

    CVE-2020-11046

    Last Modified: 21 Nov 2024

    In FreeRDP after 1.0 and before 2.0.0, there is a stream out-of-bounds seek in update_read_synchronize that could lead to a later out-of-bounds read.

    Published: 30 Mar 2020
    2.2
    Low

    CVE-2020-11045

    Last Modified: 21 Nov 2024

    In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.

    Published: 30 Mar 2020
    4.4
    Medium

    CVE-2020-10697

    Last Modified: 21 Nov 2024

    A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce the Tower performance, for which memcached is designed. Theoretically, more sophisticated attacks can be performed by manipulating and crafting the cache, as Tower relies on memcached as a place to pull out setting values. Confidential and sensitive data stored in memcached should not be pulled, as this information is encrypted. This flaw affects Ansible Tower versions before 3.6.4, Ansible Tower versions before 3.5.6 and Ansible Tower versions before 3.4.6.

    Published: 29 Mar 2020
    4.4
    Medium

    CVE-2019-20806

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

    Published: 29 Mar 2020
    8.8
    High

    CVE-2020-11113

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).

    Published: 28 Mar 2020
    7.8
    High

    CVE-2020-10940

    Last Modified: 21 Nov 2024

    Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.

    Published: 27 Mar 2020