CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2020-8134

    Last Modified: 21 Nov 2024

    Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

    Published: 20 Mar 2020
    9.8
    Critical

    CVE-2020-8137

    Last Modified: 21 Nov 2024

    Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.

    Published: 20 Mar 2020
    9.8
    Critical

    CVE-2020-8135

    Last Modified: 21 Nov 2024

    The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2020-8136

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in fastify-multipart < 1.0.5 allows an attacker to crash fastify applications parsing multipart requests by sending a specially crafted request.

    Published: 20 Mar 2020
    9.8
    Critical

    CVE-2020-7961

    Last Modified: 7 Nov 2025

    Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

    Published: 20 Mar 2020
    6.5
    Medium

    CVE-2020-10558

    Last Modified: 21 Nov 2024

    The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other miscellaneous functions from the main screen.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2020-10792

    Last Modified: 21 Nov 2024

    openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2020-9425

    Last Modified: 21 Nov 2024

    An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a GET request to settings.php. Because the application was not exiting after a redirect is applied, the rest of the page still executed, resulting in the disclosure of cleartext credentials in the response.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2019-19324

    Last Modified: 21 Nov 2024

    Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted accidental JWT acceptance.

    Published: 20 Mar 2020
    7.2
    High

    CVE-2019-15665

    Last Modified: 21 Nov 2024

    An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arbitrary write primitive that can lead to code execution or escalation of privileges.

    Published: 20 Mar 2020
    9.8
    Critical

    CVE-2019-19148

    Last Modified: 21 Nov 2024

    Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.

    Published: 20 Mar 2020
    2.7
    Low

    CVE-2019-15664

    Last Modified: 21 Nov 2024

    An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out-of-bounds read that can be used as part of a chain to escalate privileges (issue 2 of 2).

    Published: 20 Mar 2020
    2.7
    Low

    CVE-2019-15663

    Last Modified: 21 Nov 2024

    An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an out-of-bounds read that can be used as part of a chain to escalate privileges (issue 1 of 2).

    Published: 20 Mar 2020
    6.8
    Medium

    CVE-2019-16258

    Last Modified: 21 Nov 2024

    The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connecting to the internal UART interface.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2019-15075

    Last Modified: 21 Nov 2024

    An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.

    Published: 20 Mar 2020
    2.7
    Low

    CVE-2019-15662

    Last Modified: 21 Nov 2024

    An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120444 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arbitrary read primitive that can be used as part of a chain to escalate privileges.

    Published: 20 Mar 2020
    7.2
    High

    CVE-2019-15661

    Last Modified: 21 Nov 2024

    An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate parameters, leading to a stack-based buffer overflow, which can lead to code execution or escalation of privileges.

    Published: 20 Mar 2020
    3.9
    Low

    CVE-2020-1879

    Last Modified: 21 Nov 2024

    There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions 1.0.1.22(SP3);OSCA-550 versions 1.0.1.21(SP3);OSCA-550A versions 1.0.1.21(SP3);OSCA-550AX versions 1.0.1.21(SP3);OSCA-550X versions 1.0.1.21(SP3).

    Published: 20 Mar 2020
    4.6
    Medium

    CVE-2020-1794

    Last Modified: 21 Nov 2024

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

    Published: 20 Mar 2020
    8.1
    High

    CVE-2020-1864

    Last Modified: 21 Nov 2024

    Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affected device. Due to the improper implementation of the authentication function, attackers can exploit the vulnerability to connect to affected devices and execute a series of commands.Affected product versions include:Secospace AntiDDoS8000 versions V500R001C00,V500R001C20,V500R001C60,V500R005C00.

    Published: 20 Mar 2020
    4.6
    Medium

    CVE-2020-1793

    Last Modified: 21 Nov 2024

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

    Published: 20 Mar 2020
    6.6
    Medium

    CVE-2020-1796

    Last Modified: 21 Nov 2024

    There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

    Published: 20 Mar 2020
    5.5
    Medium

    CVE-2020-1878

    Last Modified: 21 Nov 2024

    Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some information by loading malicious application, leading to information leak.

    Published: 20 Mar 2020
    2.4
    Low

    CVE-2020-1795

    Last Modified: 21 Nov 2024

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

    Published: 20 Mar 2020
    3.3
    Low

    CVE-2020-1862

    Last Modified: 21 Nov 2024

    There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some service abnormal. Affected product versions include:CampusInsight versions V100R019C00;ManageOne versions 6.5.RC2.B050.

    Published: 20 Mar 2020
    7.1
    High

    CVE-2020-10597

    Last Modified: 21 Nov 2024

    Delta Industrial Automation DOPSoft, Version 4.00.08.15 and prior. Multiple out-of-bounds read vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to read information and/or crash the application.

    Published: 20 Mar 2020
    7.8
    High

    CVE-2020-10682

    Last Modified: 21 Nov 2024

    The Filemanager in CMS Made Simple 2.2.13 allows remote code execution via a .php.jpegd JPEG file, as demonstrated by m1_files[] to admin/moduleinterface.php. The file should be sent as application/octet-stream and contain PHP code (it need not be a valid JPEG file).

    Published: 20 Mar 2020
    5.4
    Medium

    CVE-2020-10681

    Last Modified: 21 Nov 2024

    The Filemanager in CMS Made Simple 2.2.13 has stored XSS via a .pxd file, as demonstrated by m1_files[] to admin/moduleinterface.php.

    Published: 20 Mar 2020
    6.1
    Medium

    CVE-2019-19484

    Last Modified: 21 Nov 2024

    Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

    Published: 20 Mar 2020
    6.5
    Medium

    CVE-2019-19486

    Last Modified: 21 Nov 2024

    Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.

    Published: 20 Mar 2020
    8.8
    High

    CVE-2019-19487

    Last Modified: 21 Nov 2024

    Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

    Published: 20 Mar 2020
    8.8
    High

    CVE-2019-19023

    Last Modified: 21 Nov 2024

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry for the Pivotal Platform.

    Published: 20 Mar 2020
    6.5
    Medium

    CVE-2020-9345

    Last Modified: 21 Nov 2024

    An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the application doesn't limit the number of opened WebSocket sockets. If a victim visits an attacker-controlled website, this vulnerability can be exploited.

    Published: 20 Mar 2020
    6.1
    Medium

    CVE-2020-9344

    Last Modified: 21 Nov 2024

    Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.

    Published: 20 Mar 2020
    6.5
    Medium

    CVE-2020-9343

    Last Modified: 21 Nov 2024

    An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the implementation doesn't limit the parsing of nested JSON structures. If a victim visits an attacker-controlled website, this vulnerability can be exploited via WebSocket data with a deeply nested JSON array.

    Published: 20 Mar 2020
    7.2
    High

    CVE-2019-19029

    Last Modified: 21 Nov 2024

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for the Pivotal Platform.

    Published: 20 Mar 2020
    4.9
    Medium

    CVE-2019-19026

    Last Modified: 21 Nov 2024

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware Harbor Container Registry for the Pivotal Platform.

    Published: 20 Mar 2020
    8.8
    High

    CVE-2019-19025

    Last Modified: 21 Nov 2024

    Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2019-18785

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.

    Published: 20 Mar 2020
    5.3
    Medium

    CVE-2019-18782

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2018-20333

    Last Modified: 21 Nov 2024

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can request /update_applist.asp to see if a USB device is attached to the router and if there are apps installed on the router.

    Published: 20 Mar 2020
    7.5
    High

    CVE-2018-20335

    Last Modified: 21 Nov 2024

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. An unauthenticated user can trigger a DoS of the httpd service via the /APP_Installation.asp?= URI.

    Published: 20 Mar 2020
    9.8
    Critical

    CVE-2018-20334

    Last Modified: 21 Nov 2024

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

    Published: 20 Mar 2020
    —
    Unknown

    CVE-2020-10692

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

    Published: 20 Mar 2020
    6.1
    Medium

    CVE-2019-13389

    Last Modified: 21 Nov 2024

    RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.

    Published: 20 Mar 2020
    —
    Unknown

    CVE-2020-10694

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

    Published: 20 Mar 2020
    6.5
    Medium

    CVE-2020-10701

    Last Modified: 21 Nov 2024

    A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.

    Published: 20 Mar 2020
    —
    Unknown

    CVE-2020-10764

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

    Published: 20 Mar 2020
    —
    Unknown

    CVE-2020-10765

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none.

    Published: 20 Mar 2020
    8.8
    High

    CVE-2019-16071

    Last Modified: 21 Nov 2024

    Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability to modify any settings in the system, only view the components. However, it is possible for a low-privileged user to perform all actions as an administrator by bypassing authorization controls and sending requests to the server in the context of an administrator.

    Published: 19 Mar 2020