CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-10557

    Last Modified: 21 Nov 2024

    An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions.

    Published: 16 Mar 2020
    7.4
    High

    CVE-2019-10091

    Last Modified: 21 Nov 2024

    When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.

    Published: 16 Mar 2020
    5.3
    Medium

    CVE-2020-9518

    Last Modified: 21 Nov 2024

    Login filter can access configuration files vulnerability in Micro Focus Service Manager (Web Tier), affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to configuration data.

    Published: 16 Mar 2020
    5.3
    Medium

    CVE-2020-9519

    Last Modified: 21 Nov 2024

    HTTP methods reveled in Web services vulnerability in Micro Focus Service manager (server), affecting versions 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow exposure of configuration data.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5547

    Last Modified: 21 Nov 2024

    Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5545

    Last Modified: 21 Nov 2024

    TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to bypass access restriction and to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    8.8
    High

    CVE-2020-5546

    Last Modified: 21 Nov 2024

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5543

    Last Modified: 21 Nov 2024

    TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5544

    Last Modified: 21 Nov 2024

    Null Pointer Dereference vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    9.8
    Critical

    CVE-2020-5542

    Last Modified: 21 Nov 2024

    Buffer error vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet.

    Published: 16 Mar 2020
    5.3
    Medium

    CVE-2020-7608

    Last Modified: 21 Nov 2024

    yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

    Published: 16 Mar 2020
    6.7
    Medium

    CVE-2019-15708

    Last Modified: 21 Nov 2024

    A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted ifconfig commands.

    Published: 15 Mar 2020
    8.8
    High

    CVE-2019-17654

    Last Modified: 21 Nov 2024

    An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.

    Published: 15 Mar 2020
    6.1
    Medium

    CVE-2019-6696

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.

    Published: 15 Mar 2020
    7.8
    High

    CVE-2020-9287

    Last Modified: 21 Nov 2024

    An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

    Published: 15 Mar 2020
    7.8
    High

    CVE-2020-9290

    Last Modified: 21 Nov 2024

    An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7603

    Last Modified: 21 Nov 2024

    closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7607

    Last Modified: 21 Nov 2024

    gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7605

    Last Modified: 21 Nov 2024

    gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7606

    Last Modified: 21 Nov 2024

    docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7604

    Last Modified: 21 Nov 2024

    pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7602

    Last Modified: 21 Nov 2024

    node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file "linux/manager.js". This function is used to construct the argument of function "execSync()", which can be controlled by users without any sanitization.

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-7601

    Last Modified: 21 Nov 2024

    gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options.

    Published: 15 Mar 2020
    9.1
    Critical

    CVE-2020-10594

    Last Modified: 21 Nov 2024

    An issue was discovered in drf-jwt 1.15.x before 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt is a fork of jpadilla/django-rest-framework-jwt, which is unmaintained.

    Published: 15 Mar 2020
    7.5
    High

    CVE-2019-9474

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-79996267

    Published: 15 Mar 2020
    7.5
    High

    CVE-2019-9473

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-115363533

    Published: 15 Mar 2020
    6.5
    Medium

    CVE-2020-0088

    Last Modified: 21 Nov 2024

    In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124389881

    Published: 15 Mar 2020
    9.8
    Critical

    CVE-2020-0086

    Last Modified: 21 Nov 2024

    In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arbitrary code execution if IntSan were not enabled, which it is by default. No additional execution privileges are required. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-131859347

    Published: 15 Mar 2020
    6.5
    Medium

    CVE-2019-2058

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android Versions: Android-10 Android ID: A-136089102

    Published: 15 Mar 2020
    5.5
    Medium

    CVE-2019-2088

    Last Modified: 21 Nov 2024

    In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were not enabled, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-143895055

    Published: 15 Mar 2020
    7.8
    High

    CVE-2019-2089

    Last Modified: 21 Nov 2024

    In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10 Android ID: A-116608833

    Published: 15 Mar 2020
    7.3
    High

    CVE-2019-2216

    Last Modified: 21 Nov 2024

    In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User interaction is needed for exploitation.Product: Android Versions: Android-10 Android ID: A-38390530

    Published: 15 Mar 2020
    7.5
    High

    CVE-2020-10591

    Last Modified: 21 Nov 2024

    An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and references to usernames via api/v1/apikey.

    Published: 15 Mar 2020
    7.8
    High

    CVE-2020-10589

    Last Modified: 21 Nov 2024

    v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restarted via Sudo.

    Published: 15 Mar 2020
    7.8
    High

    CVE-2020-10588

    Last Modified: 21 Nov 2024

    v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.

    Published: 15 Mar 2020
    8.8
    High

    CVE-2020-8141

    Last Modified: 21 Nov 2024

    The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.

    Published: 15 Mar 2020
    8.8
    High

    CVE-2020-10672

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

    Published: 15 Mar 2020
    7.8
    High

    CVE-2020-10587

    Last Modified: 21 Nov 2024

    antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.

    Published: 14 Mar 2020
    7.5
    High

    CVE-2020-10578

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.

    Published: 14 Mar 2020
    7.5
    High

    CVE-2020-10573

    Last Modified: 21 Nov 2024

    An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.

    Published: 14 Mar 2020
    9.8
    Critical

    CVE-2020-10574

    Last Modified: 21 Nov 2024

    An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.

    Published: 14 Mar 2020
    5.9
    Medium

    CVE-2020-10576

    Last Modified: 21 Nov 2024

    An issue was discovered in Janus through 0.9.1. plugins/janus_voicemail.c in the VoiceMail plugin has a race condition that could cause a server crash.

    Published: 14 Mar 2020
    4.8
    Medium

    CVE-2020-10577

    Last Modified: 21 Nov 2024

    An issue was discovered in Janus through 0.9.1. janus.c has multiple concurrent threads that misuse the source property of a session, leading to a race condition when claiming sessions.

    Published: 14 Mar 2020
    4.2
    Medium

    CVE-2020-10575

    Last Modified: 21 Nov 2024

    An issue was discovered in Janus through 0.9.1. plugins/janus_videocall.c in the VideoCall plugin mishandles session management because a race condition causes some references to be freed too early or too many times.

    Published: 14 Mar 2020
    9.8
    Critical

    CVE-2020-10571

    Last Modified: 21 Nov 2024

    An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.

    Published: 14 Mar 2020
    8.8
    High

    CVE-2020-10568

    Last Modified: 21 Nov 2024

    The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

    Published: 14 Mar 2020
    7.8
    High

    CVE-2020-10565

    Last Modified: 21 Nov 2024

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS.

    Published: 14 Mar 2020
    7.8
    High

    CVE-2020-10566

    Last Modified: 21 Nov 2024

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.

    Published: 14 Mar 2020
    9.8
    Critical

    CVE-2020-10567

    Last Modified: 21 Nov 2024

    An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php extension is used in the name parameter. (A potential fast patch is to disable the save_img action in the config file.)

    Published: 14 Mar 2020
    9.8
    Critical

    CVE-2020-10564

    Last Modified: 21 Nov 2024

    An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.

    Published: 13 Mar 2020