CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-6426

    Last Modified: 21 Nov 2024

    Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Mar 2020
    7.8
    High

    CVE-2020-3950

    Last Modified: 30 Oct 2025

    VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.

    Published: 17 Mar 2020
    3.8
    Low

    CVE-2020-3951

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a denial-of-service condition of the Thinprint service running on the system where Workstation or Horizon Client is installed.

    Published: 17 Mar 2020
    8.8
    High

    CVE-2018-21037

    Last Modified: 21 Nov 2024

    Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.

    Published: 17 Mar 2020
    5.4
    Medium

    CVE-2020-10596

    Last Modified: 21 Nov 2024

    OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.

    Published: 17 Mar 2020
    6.5
    Medium

    CVE-2020-10122

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows a webmail or demo account to delete arbitrary files (SEC-547).

    Published: 17 Mar 2020
    9.8
    Critical

    CVE-2020-10121

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).

    Published: 17 Mar 2020
    7.2
    High

    CVE-2020-10120

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).

    Published: 17 Mar 2020
    9.8
    Critical

    CVE-2020-10119

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

    Published: 17 Mar 2020
    9.1
    Critical

    CVE-2020-10118

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).

    Published: 17 Mar 2020
    9.1
    Critical

    CVE-2020-10117

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).

    Published: 17 Mar 2020
    5.3
    Medium

    CVE-2020-10116

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541).

    Published: 17 Mar 2020
    7.2
    High

    CVE-2020-10115

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).

    Published: 17 Mar 2020
    6.1
    Medium

    CVE-2020-10114

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535).

    Published: 17 Mar 2020
    6.1
    Medium

    CVE-2020-10113

    Last Modified: 21 Nov 2024

    cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515).

    Published: 17 Mar 2020
    9.8
    Critical

    CVE-2019-20498

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

    Published: 17 Mar 2020
    5.4
    Medium

    CVE-2019-20497

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).

    Published: 17 Mar 2020
    5.5
    Medium

    CVE-2019-20496

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).

    Published: 17 Mar 2020
    6.5
    Medium

    CVE-2019-20495

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).

    Published: 17 Mar 2020
    3.3
    Low

    CVE-2019-20494

    Last Modified: 21 Nov 2024

    In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).

    Published: 17 Mar 2020
    6.1
    Medium

    CVE-2019-20493

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).

    Published: 17 Mar 2020
    8.8
    High

    CVE-2019-20492

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).

    Published: 17 Mar 2020
    8.8
    High

    CVE-2019-20490

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).

    Published: 17 Mar 2020
    5.3
    Medium

    CVE-2018-18576

    Last Modified: 21 Nov 2024

    The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.

    Published: 17 Mar 2020
    7.2
    High

    CVE-2019-11074

    Last Modified: 21 Nov 2024

    A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Full Web Page Sensor and set specific settings when executing the sensor.

    Published: 17 Mar 2020
    9.8
    Critical

    CVE-2020-10380

    Last Modified: 21 Nov 2024

    RMySQL through 0.10.19 allows SQL Injection.

    Published: 17 Mar 2020
    8.8
    High

    CVE-2019-20453

    Last Modified: 21 Nov 2024

    A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.

    Published: 17 Mar 2020
    8.8
    High

    CVE-2019-20452

    Last Modified: 21 Nov 2024

    A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/core.access/src/RecycleBinManager.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.

    Published: 17 Mar 2020
    5.4
    Medium

    CVE-2020-6646

    Last Modified: 21 Nov 2024

    An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacement Message.

    Published: 17 Mar 2020
    4.3
    Medium

    CVE-2019-20407

    Last Modified: 21 Nov 2024

    The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they do not have access to through an missing authorisation check.

    Published: 17 Mar 2020
    4.9
    Medium

    CVE-2019-20105

    Last Modified: 21 Nov 2024

    The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.1, and from version 7.1.0 before version 7.1.3 allows remote attackers who have obtained access to administrator's session to access the EditApplinkServlet resource without needing to re-authenticate to pass "WebSudo" in products that support "WebSudo" through an improper access control vulnerability.

    Published: 17 Mar 2020
    9.8
    Critical

    CVE-2020-9347

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-9346

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2019-20191

    Last Modified: 21 Nov 2024

    Oxygen XML Editor 21.1.1 allows XXE to read any file.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-8784

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-8785

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-8786

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-8787

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow for an invalid Bean ID to be submitted.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-8783

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).

    Published: 16 Mar 2020
    8.1
    High

    CVE-2020-7982

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-7248

    Last Modified: 21 Nov 2024

    libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buffer overflow.

    Published: 16 Mar 2020
    5.9
    Medium

    CVE-2020-6175

    Last Modified: 21 Nov 2024

    Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

    Published: 16 Mar 2020
    4.8
    Medium

    CVE-2019-19852

    Last Modified: 21 Nov 2024

    An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report screen in the cel module at the admin/config.php?display=cel URI via date fields. This affects cel through 13.0.26.9, 14.x through 14.0.2.14, and 15.x through 15.0.15.4.

    Published: 16 Mar 2020
    4.8
    Medium

    CVE-2019-19615

    Last Modified: 21 Nov 2024

    Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown at /admin/config.php?display=backup on the FreePBX Administrator web site. An attacker can modify the id parameter of the backup configuration screen and embed malicious XSS code via a link. When another user (such as an admin) clicks the link, the XSS payload will render and execute in the context of the victim user's account.

    Published: 16 Mar 2020
    5.2
    Medium

    CVE-2019-19613

    Last Modified: 21 Nov 2024

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in Release 24.2020.20608.0

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-19612

    Last Modified: 21 Nov 2024

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site Scripting (XSS). Fixed in Release 24.2020.20608.0.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-19610

    Last Modified: 21 Nov 2024

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-20491

    Last Modified: 21 Nov 2024

    cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).

    Published: 16 Mar 2020
    7.2
    High

    CVE-2019-19538

    Last Modified: 21 Nov 2024

    In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-19461

    Last Modified: 21 Nov 2024

    Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.

    Published: 16 Mar 2020