CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-10939

    Last Modified: 21 Nov 2024

    Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-6095

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 27 Mar 2020
    6.5
    Medium

    CVE-2020-10952

    Last Modified: 21 Nov 2024

    GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-10953

    Last Modified: 21 Nov 2024

    In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-10954

    Last Modified: 21 Nov 2024

    GitLab through 12.9 is affected by a potential DoS in repository archive download.

    Published: 27 Mar 2020
    6.5
    Medium

    CVE-2020-10955

    Last Modified: 21 Nov 2024

    GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.

    Published: 27 Mar 2020
    9.8
    Critical

    CVE-2020-10956

    Last Modified: 21 Nov 2024

    GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

    Published: 27 Mar 2020
    8.8
    High

    CVE-2020-10817

    Last Modified: 21 Nov 2024

    The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-5862

    Last Modified: 21 Nov 2024

    On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any other cloud provider since the affected driver is specific to AWS.

    Published: 27 Mar 2020
    8.6
    High

    CVE-2020-5863

    Last Modified: 21 Nov 2024

    In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-5861

    Last Modified: 21 Nov 2024

    On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stored data resulting in memory errors.

    Published: 27 Mar 2020
    7.8
    High

    CVE-2020-5858

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands with elevated privilege via a crafted tmsh command.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-5859

    Last Modified: 21 Nov 2024

    On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file.

    Published: 27 Mar 2020
    8.1
    High

    CVE-2020-5860

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover traffic is not encrypted by Transport Layer Security (TLS).

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-5857

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior may lead to a denial of service.

    Published: 27 Mar 2020
    9.8
    Critical

    CVE-2015-5684

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.

    Published: 27 Mar 2020
    7.8
    High

    CVE-2015-7334

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code with elevated privileges.

    Published: 27 Mar 2020
    7.8
    High

    CVE-2015-8534

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges.

    Published: 27 Mar 2020
    7
    High

    CVE-2015-7335

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2015-7336

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.

    Published: 27 Mar 2020
    7.8
    High

    CVE-2015-7333

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a user to execute arbitrary code with elevated privileges.

    Published: 27 Mar 2020
    7.8
    High

    CVE-2015-8535

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary code with elevated privileges.

    Published: 27 Mar 2020
    8.8
    High

    CVE-2015-8536

    Last Modified: 21 Nov 2024

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site request forgery.

    Published: 27 Mar 2020
    5.4
    Medium

    CVE-2020-7918

    Last Modified: 21 Nov 2024

    An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

    Published: 27 Mar 2020
    8.8
    High

    CVE-2020-10607

    Last Modified: 21 Nov 2024

    In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

    Published: 27 Mar 2020
    7.3
    High

    CVE-2020-1773

    Last Modified: 21 Nov 2024

    An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS; 7.0.15 and prior versions.

    Published: 27 Mar 2020
    6.5
    Medium

    CVE-2020-1772

    Last Modified: 21 Nov 2024

    It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Community Edition 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

    Published: 27 Mar 2020
    4.6
    Medium

    CVE-2020-1771

    Last Modified: 21 Nov 2024

    Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

    Published: 27 Mar 2020
    2.4
    Low

    CVE-2020-1770

    Last Modified: 21 Nov 2024

    Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

    Published: 27 Mar 2020
    3.5
    Low

    CVE-2020-1769

    Last Modified: 21 Nov 2024

    In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. This issue affects: ((OTRS)) Community Edition: 5.0.41 and prior versions, 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

    Published: 27 Mar 2020
    8.1
    High

    CVE-2020-10510

    Last Modified: 21 Nov 2024

    Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

    Published: 27 Mar 2020
    6.1
    Medium

    CVE-2020-10509

    Last Modified: 21 Nov 2024

    Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), attackers can inject arbitrary command into the system and launch XSS attack.

    Published: 27 Mar 2020
    7.5
    High

    CVE-2020-10508

    Last Modified: 21 Nov 2024

    Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information.

    Published: 27 Mar 2020
    10
    Critical

    CVE-2020-3936

    Last Modified: 21 Nov 2024

    UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

    Published: 27 Mar 2020
    8.6
    High

    CVE-2020-3921

    Last Modified: 21 Nov 2024

    UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.

    Published: 27 Mar 2020
    8.1
    High

    CVE-2020-3920

    Last Modified: 21 Nov 2024

    UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.

    Published: 27 Mar 2020
    3.3
    Low

    CVE-2020-10698

    Last Modified: 21 Nov 2024

    A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed jobs which are run from other organizations. Some sensible data can be disclosed. However, critical data should not be disclosed, as it should be protected by the no_log flag when debugging is enabled. This flaw affects Ansible Tower versions before 3.6.4, Ansible Tower versions before 3.5.6 and Ansible Tower versions before 3.4.6.

    Published: 27 Mar 2020
    6.5
    Medium

    CVE-2019-11254

    Last Modified: 21 Nov 2024

    The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.

    Published: 27 Mar 2020
    5.2
    Medium

    CVE-2020-10691

    Last Modified: 21 Nov 2024

    An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

    Published: 27 Mar 2020
    7.4
    High

    CVE-2020-11501

    Last Modified: 21 Nov 2024

    GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.

    Published: 27 Mar 2020
    9.8
    Critical

    CVE-2020-10990

    Last Modified: 21 Nov 2024

    An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10991

    Last Modified: 21 Nov 2024

    Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10992

    Last Modified: 21 Nov 2024

    Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.

    Published: 26 Mar 2020
    9.1
    Critical

    CVE-2020-10993

    Last Modified: 21 Nov 2024

    Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.

    Published: 26 Mar 2020
    4.3
    Medium

    CVE-2020-9468

    Last Modified: 21 Nov 2024

    The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.

    Published: 26 Mar 2020
    5.4
    Medium

    CVE-2020-9467

    Last Modified: 21 Nov 2024

    Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10828

    Last Modified: 5 May 2025

    A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10827

    Last Modified: 5 May 2025

    A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10826

    Last Modified: 5 May 2025

    /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10825

    Last Modified: 5 May 2025

    A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).

    Published: 26 Mar 2020