CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-18917

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2019-19212

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2020-9472

    Last Modified: 21 Nov 2024

    Umbraco CMS 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package functionality.

    Published: 16 Mar 2020
    7.2
    High

    CVE-2019-19937

    Last Modified: 21 Nov 2024

    In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-9471

    Last Modified: 21 Nov 2024

    Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Packages functionality.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2017-12842

    Last Modified: 21 Nov 2024

    Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more than a million dollars, and is relevant mainly only in situations where an autonomous system relies solely on an SPV proof for transactions of a greater dollar amount.

    Published: 16 Mar 2020
    7.2
    High

    CVE-2019-11073

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Transaction Sensor and set specific settings when the sensor is executed.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-9321

    Last Modified: 6 Mar 2026

    configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.

    Published: 16 Mar 2020
    —
    Unknown

    CVE-2018-19325

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14466. Reason: This candidate is a duplicate of CVE-2018-14466. Notes: All CVE users should reference CVE-2018-14466 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2019-19946

    Last Modified: 21 Nov 2024

    The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

    Published: 16 Mar 2020
    7.8
    High

    CVE-2019-5543

    Last Modified: 21 Nov 2024

    For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed may exploit this issue to run commands as any user.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-5849

    Last Modified: 17 Mar 2026

    Unraid 6.8.0 allows authentication bypass.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5847

    Last Modified: 17 Mar 2026

    Unraid through 6.8.0 allows Remote Code Execution.

    Published: 16 Mar 2020
    7.2
    High

    CVE-2020-5844

    Last Modified: 21 Nov 2024

    index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-3947

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.

    Published: 16 Mar 2020
    7.8
    High

    CVE-2020-3948

    Last Modified: 21 Nov 2024

    Linux Guest VMs running on VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a local privilege escalation vulnerability due to improper file permissions in Cortado Thinprint. Local attackers with non-administrative access to a Linux guest VM with virtual printing enabled may exploit this issue to elevate their privileges to root on the same guest VM.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2019-19945

    Last Modified: 21 Nov 2024

    uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.

    Published: 16 Mar 2020
    8.1
    High

    CVE-2019-19821

    Last Modified: 21 Nov 2024

    A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information and modify information with administrative privileges by not following the HTTP Location header in server responses. This is fixed in all iTop packages (community, essential, professional) in versions : 2.5.4, 2.6.3, 2.7.0

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2020-7916

    Last Modified: 21 Nov 2024

    be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role to an instructor/teacher and gain access to otherwise restricted data.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-10243

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

    Published: 16 Mar 2020
    6.1
    Medium

    CVE-2020-10242

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allows XSS attacks.

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-10241

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.

    Published: 16 Mar 2020
    7.4
    High

    CVE-2019-19135

    Last Modified: 21 Nov 2024

    In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.

    Published: 16 Mar 2020
    5.3
    Medium

    CVE-2020-10240

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-10239

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-10238

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-6984

    Last Modified: 3 Jun 2026

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-6990

    Last Modified: 3 Jun 2026

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could identify cryptographic keys and use it for further cryptographic attacks that could ultimately lead to a remote attacker gaining unauthorized access to the controller.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2020-6988

    Last Modified: 3 Jun 2026

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether, disclose sensitive information, or leak credentials.

    Published: 16 Mar 2020
    3.3
    Low

    CVE-2020-6980

    Last Modified: 21 Nov 2024

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-10230

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2020-6584

    Last Modified: 21 Nov 2024

    Nagios Log Server 2.1.3 has Incorrect Access Control.

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-6585

    Last Modified: 21 Nov 2024

    Nagios Log Server 2.1.3 has CSRF.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2020-6586

    Last Modified: 21 Nov 2024

    Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.

    Published: 16 Mar 2020
    5.5
    Medium

    CVE-2019-4719

    Last Modified: 21 Nov 2024

    IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2019-4656

    Last Modified: 21 Nov 2024

    IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that would allow an authenticated user to crash the queue and require a restart due to an error processing error messages. IBM X-Force ID: 170967.

    Published: 16 Mar 2020
    5.5
    Medium

    CVE-2019-4619

    Last Modified: 21 Nov 2024

    IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 168862.

    Published: 16 Mar 2020
    4.4
    Medium

    CVE-2019-4617

    Last Modified: 21 Nov 2024

    IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 168645.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2019-19942

    Last Modified: 21 Nov 2024

    Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-19941

    Last Modified: 21 Nov 2024

    Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS.

    Published: 16 Mar 2020
    7.2
    High

    CVE-2019-19940

    Last Modified: 21 Nov 2024

    Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection.

    Published: 16 Mar 2020
    4.8
    Medium

    CVE-2019-19851

    Last Modified: 21 Nov 2024

    An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Superfecta module at the admin/config.php?display=superfecta URI. This affects Superfecta through 13.0.4.7, 14.x through 14.0.24, and 15.x through 15.0.2.20.

    Published: 16 Mar 2020
    6.1
    Medium

    CVE-2019-19211

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.

    Published: 16 Mar 2020
    5.4
    Medium

    CVE-2019-19210

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2019-19209

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2019-19208

    Last Modified: 21 Nov 2024

    Codiad Web IDE through 2.8.4 allows PHP Code injection.

    Published: 16 Mar 2020
    6.1
    Medium

    CVE-2019-14512

    Last Modified: 21 Nov 2024

    LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.

    Published: 16 Mar 2020
    6.1
    Medium

    CVE-2018-10125

    Last Modified: 21 Nov 2024

    Contao before 4.5.7 has XSS in the system log.

    Published: 16 Mar 2020
    7.5
    High

    CVE-2018-13063

    Last Modified: 21 Nov 2024

    Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

    Published: 16 Mar 2020
    6.5
    Medium

    CVE-2018-13060

    Last Modified: 21 Nov 2024

    Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

    Published: 16 Mar 2020