CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-10824

    Last Modified: 5 May 2025

    A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10823

    Last Modified: 5 May 2025

    A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3).

    Published: 26 Mar 2020
    5.5
    Medium

    CVE-2020-9065

    Last Modified: 21 Nov 2024

    Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may tamper with the information to affect the availability.

    Published: 26 Mar 2020
    7.8
    High

    CVE-2020-1800

    Last Modified: 21 Nov 2024

    HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing a crafted application, successful exploit could allow the attacker do certain unauthenticated operations.

    Published: 26 Mar 2020
    7.8
    High

    CVE-2020-9066

    Last Modified: 21 Nov 2024

    Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application doesn't perform proper authentication when user performs certain operations. An attacker can trick user into installing a malicious plug-in to exploit this vulnerability. Successful exploit could allow the attacker to bypass the authentication to perform unauthorized operations.

    Published: 26 Mar 2020
    8.8
    High

    CVE-2020-9521

    Last Modified: 21 Nov 2024

    An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead to the product being vulnerable to SQL injection.

    Published: 26 Mar 2020
    7.7
    High

    CVE-2020-7944

    Last Modified: 21 Nov 2024

    In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.

    Published: 26 Mar 2020
    7.5
    High

    CVE-2019-5105

    Last Modified: 21 Nov 2024

    An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).

    Published: 26 Mar 2020
    7.5
    High

    CVE-2020-4276

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.

    Published: 26 Mar 2020
    4.7
    Medium

    CVE-2019-15796

    Last Modified: 21 Nov 2024

    Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py or in `_fetch_archives()` of apt/cache.py in version 1.9.3ubuntu2 and earlier. This allows downloads from unsigned repositories which shouldn't be allowed and has been fixed in verisions 1.9.5, 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.

    Published: 26 Mar 2020
    4.7
    Medium

    CVE-2019-15795

    Last Modified: 21 Nov 2024

    python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py in version 1.9.0ubuntu1 and earlier. This allows a man-in-the-middle attack which could potentially be used to install altered packages and has been fixed in versions 1.9.0ubuntu1.2, 1.6.5ubuntu0.1, 1.1.0~beta1ubuntu0.16.04.7, 0.9.3.5ubuntu3+esm2, and 0.8.3ubuntu7.5.

    Published: 26 Mar 2020
    6.5
    Medium

    CVE-2020-6999

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer.

    Published: 26 Mar 2020
    6.5
    Medium

    CVE-2020-8910

    Last Modified: 21 Nov 2024

    A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authority. Mitigation: update your library to version v20200315.

    Published: 26 Mar 2020
    5.4
    Medium

    CVE-2020-8923

    Last Modified: 21 Nov 2024

    An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements.

    Published: 26 Mar 2020
    7.3
    High

    CVE-2020-7260

    Last Modified: 21 Nov 2024

    DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

    Published: 26 Mar 2020
    9.8
    Critical

    CVE-2020-10245

    Last Modified: 21 Nov 2024

    CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.

    Published: 26 Mar 2020
    7.5
    High

    CVE-2020-5129

    Last Modified: 21 Nov 2024

    A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier.

    Published: 26 Mar 2020
    8.8
    High

    CVE-2020-10696

    Last Modified: 21 Nov 2024

    A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.

    Published: 26 Mar 2020
    7.8
    High

    CVE-2020-36313

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.

    Published: 26 Mar 2020
    8.1
    High

    CVE-2020-10965

    Last Modified: 21 Nov 2024

    Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled. It is fixed in 20.01.1 and 19.11.2.

    Published: 25 Mar 2020
    6.5
    Medium

    CVE-2020-10966

    Last Modified: 21 Nov 2024

    In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL containing an attacker-controlled server name.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-10964

    Last Modified: 21 Nov 2024

    Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.

    Published: 25 Mar 2020
    7.2
    High

    CVE-2020-10963

    Last Modified: 21 Nov 2024

    FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

    Published: 25 Mar 2020
    4.8
    Medium

    CVE-2020-5340

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser.

    Published: 25 Mar 2020
    4.8
    Medium

    CVE-2020-5339

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser.

    Published: 25 Mar 2020
    5.4
    Medium

    CVE-2020-9520

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3776

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    7.5
    High

    CVE-2020-3777

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    4.3
    Medium

    CVE-2020-3778

    Last Modified: 21 Nov 2024

    Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3788

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    4.3
    Medium

    CVE-2020-3771

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3779

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3790

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3775

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    4.3
    Medium

    CVE-2020-3791

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3774

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3789

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3773

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    4.3
    Medium

    CVE-2020-3781

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3772

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3785

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3784

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3780

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3783

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a heap corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3787

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    4.3
    Medium

    CVE-2020-3782

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-3770

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-3786

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-10887

    Last Modified: 21 Nov 2024

    This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections. The issue results from the lack of proper filtering of IPv6 SSH connections. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9663.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-10888

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port forwarding requests during initial setup. The issue results from the lack of proper authentication prior to establishing SSH port forwarding rules. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the WAN interface. Was ZDI-CAN-9664.

    Published: 25 Mar 2020