CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-12132

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

    Published: 18 Mar 2020
    9.1
    Critical

    CVE-2019-12124

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2019-12123

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.

    Published: 18 Mar 2020
    6.5
    Medium

    CVE-2019-12122

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an attacker who possesses a user's cookie may retrieve that user's password from the database. All Portal setups are affected.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2019-12121

    Last Modified: 21 Nov 2024

    An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12120

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12119

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12118

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12117

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12116

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12115

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12114

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2019-12113

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2019-12112

    Last Modified: 21 Nov 2024

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

    Published: 18 Mar 2020
    6.5
    Medium

    CVE-2019-14871

    Last Modified: 21 Nov 2024

    The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP and other newlib macros in versions prior to 3.3.0, does not check for memory allocation problems when the DEBUG flag is unset (as is the case in production firmware builds).

    Published: 18 Mar 2020
    7.5
    High

    CVE-2019-10682

    Last Modified: 21 Nov 2024

    django-nopassword before 5.0.0 stores cleartext secrets in the database.

    Published: 18 Mar 2020
    8.1
    High

    CVE-2019-11689

    Last Modified: 21 Nov 2024

    An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.

    Published: 18 Mar 2020
    7.4
    High

    CVE-2019-11688

    Last Modified: 21 Nov 2024

    An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any certificate for asustornasapi.asustor.com. In other words, there is Missing SSL Certificate Validation.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2020-9326

    Last Modified: 21 Nov 2024

    BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a DefendpointService.exe crash.

    Published: 18 Mar 2020
    4.3
    Medium

    CVE-2020-4199

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2020-9325

    Last Modified: 21 Nov 2024

    Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2020-9324

    Last Modified: 21 Nov 2024

    Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.

    Published: 18 Mar 2020
    5.3
    Medium

    CVE-2020-9323

    Last Modified: 21 Nov 2024

    Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.

    Published: 18 Mar 2020
    5.5
    Medium

    CVE-2020-6976

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack of validation.

    Published: 18 Mar 2020
    7.8
    High

    CVE-2020-7002

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2020-9443

    Last Modified: 21 Nov 2024

    Zulip Desktop before 4.0.3 loaded untrusted content in an Electron webview with web security disabled, which can be exploited for XSS in a number of ways. This especially affects Zulip Desktop 2.3.82.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-14881

    Last Modified: 21 Nov 2024

    A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-14884

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

    Published: 18 Mar 2020
    5.3
    Medium

    CVE-2019-14883

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-14882

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-3922

    Last Modified: 21 Nov 2024

    LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter manipulation.

    Published: 18 Mar 2020
    4.3
    Medium

    CVE-2020-10659

    Last Modified: 21 Nov 2024

    Entrust Entelligence Security Provider (ESP) before 10.0.60 on Windows mishandles errors during SSL Certificate Validation, leading to situations where (for example) a user continues to interact with a web site that has an invalid certificate chain.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-8600

    Last Modified: 21 Nov 2024

    Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-8599

    Last Modified: 31 Oct 2025

    Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2020-8470

    Last Modified: 21 Nov 2024

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-8598

    Last Modified: 21 Nov 2024

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-8467

    Last Modified: 31 Oct 2025

    A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-8468

    Last Modified: 31 Oct 2025

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.

    Published: 18 Mar 2020
    —
    Unknown

    CVE-2019-20510

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13456. Reason: This candidate is a duplicate of CVE-2019-13456. Notes: All CVE users should reference CVE-2019-13456 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-10673

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

    Published: 18 Mar 2020
    5
    Medium

    CVE-2020-10685

    Last Modified: 21 Nov 2024

    A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot and the decryp emains when the host is switched off. The system will be vulnerable when the system is not running. So decrypted data must be cleared as soon as possible and the data which normally is encrypted ble.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2019-11939

    Last Modified: 21 Nov 2024

    Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6427

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6428

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    5.5
    Medium

    CVE-2020-1950

    Last Modified: 21 Nov 2024

    A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

    Published: 18 Mar 2020
    5.4
    Medium

    CVE-2020-6425

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6429

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6449

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6422

    Last Modified: 21 Nov 2024

    Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2020-6424

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020