CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-2167

    Last Modified: 21 Nov 2024

    Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

    Published: 25 Mar 2020
    5.4
    Medium

    CVE-2020-10790

    Last Modified: 21 Nov 2024

    openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.

    Published: 25 Mar 2020
    6.5
    Medium

    CVE-2020-10791

    Last Modified: 21 Nov 2024

    app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-5561

    Last Modified: 21 Nov 2024

    Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 25 Mar 2020
    6.1
    Medium

    CVE-2020-5559

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in WL-Enq 1.11 and 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-5560

    Last Modified: 21 Nov 2024

    WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-5556

    Last Modified: 21 Nov 2024

    Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 25 Mar 2020
    6.1
    Medium

    CVE-2020-5557

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-5558

    Last Modified: 21 Nov 2024

    CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 25 Mar 2020
    9.1
    Critical

    CVE-2020-5554

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write arbitrary files via unspecified vectors.

    Published: 25 Mar 2020
    9.1
    Critical

    CVE-2020-5555

    Last Modified: 21 Nov 2024

    Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper input validation issue.

    Published: 25 Mar 2020
    6.1
    Medium

    CVE-2020-5552

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-5553

    Last Modified: 21 Nov 2024

    mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 25 Mar 2020
    8.2
    High

    CVE-2020-5261

    Last Modified: 21 Nov 2024

    Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detection is an important defence in depth measure for Single Sign On solutions. The 2.5.0 version is patched. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 have a faulty implementation of Token Replay Detection. Token Replay Detection is an important defense measure for Single Sign On solutions. The 2.5.0 version is patched. Note that version 1.0.1 and prior versions are not affected. These versions have a correct Token Replay Implementation and are safe to use.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-11112

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).

    Published: 25 Mar 2020
    5.5
    Medium

    CVE-2020-8832

    Last Modified: 21 Nov 2024

    The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.

    Published: 25 Mar 2020
    8.8
    High

    CVE-2020-2160

    Last Modified: 21 Nov 2024

    Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

    Published: 25 Mar 2020
    5.4
    Medium

    CVE-2020-2162

    Last Modified: 21 Nov 2024

    Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.

    Published: 25 Mar 2020
    9.8
    Critical

    CVE-2020-1957

    Last Modified: 21 Nov 2024

    Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

    Published: 25 Mar 2020
    5.4
    Medium

    CVE-2020-2161

    Last Modified: 21 Nov 2024

    Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.

    Published: 25 Mar 2020
    6.1
    Medium

    CVE-2020-6816

    Last Modified: 21 Nov 2024

    In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.

    Published: 24 Mar 2020
    6.1
    Medium

    CVE-2020-6802

    Last Modified: 21 Nov 2024

    In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.

    Published: 24 Mar 2020
    7.8
    High

    CVE-2019-4001

    Last Modified: 21 Nov 2024

    Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

    Published: 24 Mar 2020
    —
    Unknown

    CVE-2019-19347

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6080

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through the function rr_read_RR [5] reads the current resource record, except for the RDATA section. This is read by the loop at in rr_read. For each RR type, a different function is called. When the RR type is 0x10, the function rr_read_TXT is called at [6].

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6079

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through decoding of the domain name performed by rr_decode.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-6072

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6071

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the resource record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the compression pointer is followed without checking for recursion, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6073

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA section in a TXT record in mDNS messages, multiple integer overflows can be triggered, leading to a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6078

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return value of the mdns_read_header function is not checked, leading to an uninitialized variable usage that eventually results in a null pointer dereference, leading to service crash. An attacker can send a series of mDNS messages to trigger this vulnerability.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6077

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages, the implementation does not properly keep track of the available data in the message, possibly leading to an out-of-bounds read that would result in a denial of service. An attacker can send an mDNS message to trigger this vulnerability.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6997

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-6991

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-6981

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-6979

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-7001

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-7007

    Last Modified: 21 Nov 2024

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-8986

    Last Modified: 21 Nov 2024

    lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.

    Published: 24 Mar 2020
    8.8
    High

    CVE-2020-8985

    Last Modified: 21 Nov 2024

    ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-8984

    Last Modified: 21 Nov 2024

    lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

    Published: 24 Mar 2020
    7.2
    High

    CVE-2020-6978

    Last Modified: 21 Nov 2024

    In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.

    Published: 24 Mar 2020
    8.8
    High

    CVE-2020-6982

    Last Modified: 21 Nov 2024

    In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.

    Published: 24 Mar 2020
    8.8
    High

    CVE-2020-7005

    Last Modified: 21 Nov 2024

    In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.

    Published: 24 Mar 2020
    5.3
    Medium

    CVE-2019-20593

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2019-20576

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).

    Published: 24 Mar 2020
    3.3
    Low

    CVE-2019-20625

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).

    Published: 24 Mar 2020
    5.3
    Medium

    CVE-2019-20624

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (February 2019).

    Published: 24 Mar 2020
    3.3
    Low

    CVE-2019-20623

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2019-20622

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband stack overflow. The Samsung ID is SVE-2018-13188 (February 2019).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2019-20621

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

    Published: 24 Mar 2020