CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2020-5240

    Last Modified: 21 Nov 2024

    In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA devices and potentially compromise the account if they figure out their password. The problem has been patched in version 1.4.1.

    Published: 13 Mar 2020
    7.7
    High

    CVE-2020-5257

    Last Modified: 21 Nov 2024

    In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present a SQL injection if the attacker were able to modify the `direction` parameter and bypass ActiveRecord SQL protections. Whilst this does have a high-impact, to exploit this you need access to the Administrate dashboards, which we would expect to be behind authentication. This is patched in wersion 0.13.0.

    Published: 13 Mar 2020
    7.2
    High

    CVE-2020-10562

    Last Modified: 21 Nov 2024

    An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2020-10563

    Last Modified: 21 Nov 2024

    An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.

    Published: 13 Mar 2020
    6.4
    Medium

    CVE-2019-3770

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.

    Published: 13 Mar 2020
    6.4
    Medium

    CVE-2019-3769

    Last Modified: 21 Nov 2024

    Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.

    Published: 13 Mar 2020
    9
    Critical

    CVE-2019-18578

    Last Modified: 21 Nov 2024

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malicious remote user of XtremIO may exploit this vulnerability to store malicious HTML or JavaScript code in application fields. When victim users access the injected page through their browsers, the malicious code may be executed by the web browser in the context of the vulnerable web application.

    Published: 13 Mar 2020
    6.7
    Medium

    CVE-2019-18577

    Last Modified: 21 Nov 2024

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.

    Published: 13 Mar 2020
    6.7
    Medium

    CVE-2019-18576

    Last Modified: 21 Nov 2024

    Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access to the log files may use the exposed passwords to gain access to XtremIO with the privileges of the compromised user.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-19611

    Last Modified: 21 Nov 2024

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to access the list of connected users as well as the session cookie for each user. Fixed in Release 10.24.11206.1

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-14299

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did not implement account lockout. Therefore, it was possible to obtain the local account credentials by brute force.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-14303

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD service implementation that lead to a denial of service vulnerability.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-14309

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-14310

    Last Modified: 21 Nov 2024

    Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3). Unauthenticated crafted packets to the IPP service will cause a vulnerable device to crash. A memory corruption has been identified in the way of how the embedded device parsed the IPP packets

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13192

    Last Modified: 21 Nov 2024

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.

    Published: 13 Mar 2020
    8.8
    High

    CVE-2019-13193

    Last Modified: 21 Nov 2024

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-13194

    Last Modified: 21 Nov 2024

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13165

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-13166

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2019-13167

    Last Modified: 21 Nov 2024

    Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13168

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13169

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.

    Published: 13 Mar 2020
    6.5
    Medium

    CVE-2019-13170

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13171

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register parameters, because the size used within a memcpy() function, which copied the action value into a local variable, was not checked properly.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13172

    Last Modified: 21 Nov 2024

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-13195

    Last Modified: 21 Nov 2024

    The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders existed within the file system.

    Published: 13 Mar 2020
    8.8
    High

    CVE-2019-13196

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the arg4 and arg9 parameters of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13197

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the URI paths of the web application that would allow an unauthenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2019-13198

    Last Modified: 21 Nov 2024

    The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Stored XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.

    Published: 13 Mar 2020
    6.5
    Medium

    CVE-2019-13199

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2019-13200

    Last Modified: 21 Nov 2024

    The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Reflected XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13201

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) in the LPD service and potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13202

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several functionalities of the web application that would allow an unauthenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    8.8
    High

    CVE-2019-13203

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by an integer overflow vulnerability in the arg3 parameter of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13204

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by multiple buffer overflow vulnerabilities in the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS), and potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-13205

    Last Modified: 21 Nov 2024

    All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected. However, all files that contained the configuration parameters were accessible. These files contained sensitive information, such as users, community strings, and other passwords configured in the printer.

    Published: 13 Mar 2020
    8.8
    High

    CVE-2019-13206

    Last Modified: 21 Nov 2024

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in multiple parameters of the Document Boxes functionality of the web application that would allow an authenticated attacker to perform a Denial of Service attack, crashing the device, or potentially execute arbitrary code on the device.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2019-13393

    Last Modified: 21 Nov 2024

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an attack against WPA2 could be used to determine this passphrase.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2019-13394

    Last Modified: 21 Nov 2024

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.

    Published: 13 Mar 2020
    8.8
    High

    CVE-2019-13395

    Last Modified: 21 Nov 2024

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.

    Published: 13 Mar 2020
    7.5
    High

    CVE-2020-10073

    Last Modified: 21 Nov 2024

    GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2020-10074

    Last Modified: 21 Nov 2024

    GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2020-10075

    Last Modified: 21 Nov 2024

    GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2020-10076

    Last Modified: 21 Nov 2024

    GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

    Published: 13 Mar 2020
    9.8
    Critical

    CVE-2020-10077

    Last Modified: 21 Nov 2024

    GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.

    Published: 13 Mar 2020
    6.1
    Medium

    CVE-2020-10078

    Last Modified: 21 Nov 2024

    GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

    Published: 13 Mar 2020
    5.3
    Medium

    CVE-2020-10079

    Last Modified: 21 Nov 2024

    GitLab 7.10 through 12.8.1 has Incorrect Access Control. Under certain conditions where users should have been required to configure two-factor authentication, it was not being required.

    Published: 13 Mar 2020
    5.3
    Medium

    CVE-2020-10080

    Last Modified: 21 Nov 2024

    GitLab 8.3 through 12.8.1 allows Information Disclosure. It was possible for certain non-members to access the Contribution Analytics page of a private group.

    Published: 13 Mar 2020
    6.5
    Medium

    CVE-2020-10081

    Last Modified: 21 Nov 2024

    GitLab before 12.8.2 has Incorrect Access Control. It was internally discovered that the LFS import process could potentially be used to incorrectly access LFS objects not owned by the user.

    Published: 13 Mar 2020
    5.3
    Medium

    CVE-2020-10082

    Last Modified: 21 Nov 2024

    GitLab 12.2 through 12.8.1 allows Denial of Service. A denial of service vulnerability impacting the designs for public issues was discovered.

    Published: 13 Mar 2020