CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-9101

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.

    Published: 11 Mar 2020
    5.3
    Medium

    CVE-2019-9097

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A high rate of transit traffic may cause a low-memory condition and a denial of service.

    Published: 11 Mar 2020
    8.8
    High

    CVE-2019-9102

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.

    Published: 11 Mar 2020
    7.5
    High

    CVE-2019-9104

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

    Published: 11 Mar 2020
    7.5
    High

    CVE-2019-9098

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.

    Published: 11 Mar 2020
    5.3
    Medium

    CVE-2019-9103

    Last Modified: 21 Nov 2024

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in WEB-service without authorization.

    Published: 11 Mar 2020
    9.8
    Critical

    CVE-2020-10376

    Last Modified: 21 Nov 2024

    Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header.

    Published: 11 Mar 2020
    9.8
    Critical

    CVE-2020-5203

    Last Modified: 21 Nov 2024

    In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method.

    Published: 11 Mar 2020
    6.1
    Medium

    CVE-2019-19381

    Last Modified: 21 Nov 2024

    oauth/oauth2/v1/saml/ in Abacus OAuth Login 2019_01_r4_20191021_0000 before prior to R4 (20.11.2019 Hotfix) allows Reflected Cross Site Scripting (XSS) via an error message.

    Published: 11 Mar 2020
    4.3
    Medium

    CVE-2019-16107

    Last Modified: 21 Nov 2024

    Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.

    Published: 11 Mar 2020
    5.4
    Medium

    CVE-2020-10385

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

    Published: 11 Mar 2020
    9.8
    Critical

    CVE-2020-10108

    Last Modified: 25 Nov 2024

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

    Published: 11 Mar 2020
    9.8
    Critical

    CVE-2020-10109

    Last Modified: 25 Nov 2024

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.

    Published: 11 Mar 2020
    5.5
    Medium

    CVE-2019-5106

    Last Modified: 21 Nov 2024

    A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain text.

    Published: 10 Mar 2020
    7.5
    High

    CVE-2019-5107

    Last Modified: 21 Nov 2024

    A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes passwords, configurations, and binaries being transferred to endpoints.

    Published: 10 Mar 2020
    7.5
    High

    CVE-2019-5134

    Last Modified: 21 Nov 2024

    An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting in sensitive information disclosure.

    Published: 10 Mar 2020
    9.1
    Critical

    CVE-2019-5161

    Last Modified: 21 Nov 2024

    An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.

    Published: 10 Mar 2020
    9.8
    Critical

    CVE-2019-10807

    Last Modified: 21 Nov 2024

    Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.

    Published: 10 Mar 2020
    7.2
    High

    CVE-2019-5156

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

    Published: 10 Mar 2020
    7.2
    High

    CVE-2019-5157

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.

    Published: 10 Mar 2020
    7.8
    High

    CVE-2019-5158

    Last Modified: 21 Nov 2024

    An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a newer firmware version is being installed. An attacker can create a custom firmware update package with invalid metadata in order to trigger this vulnerability.

    Published: 10 Mar 2020
    7.8
    High

    CVE-2019-5159

    Last Modified: 21 Nov 2024

    An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update, potentially resulting in code execution. An attacker can create a malicious firmware update package file using any zip utility. The user must initiate a firmware update through e!COCKPIT and choose the malicious wup file using the file browser to trigger the vulnerability.

    Published: 10 Mar 2020
    9.1
    Critical

    CVE-2019-5160

    Last Modified: 21 Nov 2024

    An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.

    Published: 10 Mar 2020
    7.8
    High

    CVE-2019-5168

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the extracted domainname value from the xml file is used as an argument to /etc/config-tools/edit_dns_server domain-name=<contents of domainname node> using sprintf().This command is later executed via a call to system().

    Published: 10 Mar 2020
    7.8
    High

    CVE-2019-5167

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d dns-server-name=<contents of dns node> using sprintf(). This command is later executed via a call to system(). This is done in a loop and there is no limit to how many dns entries will be parsed from the xml file.

    Published: 10 Mar 2020
    7.8
    High

    CVE-2019-5166

    Last Modified: 21 Nov 2024

    An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a specially crafted packet to trigger the parsing of this cache file.

    Published: 10 Mar 2020
    5.3
    Medium

    CVE-2019-5135

    Last Modified: 21 Nov 2024

    An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12).

    Published: 10 Mar 2020
    7.5
    High

    CVE-2019-5149

    Last Modified: 21 Nov 2024

    The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default configuration of this module appears to limit the number of concurrent php-cgi processes to two, which can be abused to cause a denial of service of the entire web server. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12) and version 03.02.02(14).

    Published: 10 Mar 2020
    7.2
    High

    CVE-2019-5155

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)

    Published: 10 Mar 2020
    7.5
    High

    CVE-2019-3553

    Last Modified: 21 Nov 2024

    C++ Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.02.03.00.

    Published: 10 Mar 2020
    7.5
    High

    CVE-2019-11938

    Last Modified: 21 Nov 2024

    Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.

    Published: 10 Mar 2020
    5.4
    Medium

    CVE-2020-10372

    Last Modified: 21 Nov 2024

    Ramp AltitudeCDN Altimeter before 2.4.0 allows authenticated Stored XSS via the vdms/ipmapping.jsp location field to the dms/rest/services/datastore/createOrEditValueForKey URI.

    Published: 10 Mar 2020
    6.1
    Medium

    CVE-2020-6210

    Last Modified: 21 Nov 2024

    SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Mar 2020
    7.5
    High

    CVE-2020-6209

    Last Modified: 21 Nov 2024

    SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.

    Published: 10 Mar 2020
    8.2
    High

    CVE-2020-6208

    Last Modified: 21 Nov 2024

    SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution. Although the mode of attack is only Local, multiple applications can be impacted as a result of the vulnerability.

    Published: 10 Mar 2020
    9.8
    Critical

    CVE-2020-6207

    Last Modified: 31 Oct 2025

    SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

    Published: 10 Mar 2020
    4.3
    Medium

    CVE-2020-6206

    Last Modified: 21 Nov 2024

    SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.

    Published: 10 Mar 2020
    6.1
    Medium

    CVE-2020-6205

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user, leading to Reflected Cross Site Scripting Vulnerability.

    Published: 10 Mar 2020
    4.3
    Medium

    CVE-2020-6204

    Last Modified: 21 Nov 2024

    The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.

    Published: 10 Mar 2020
    9.1
    Critical

    CVE-2020-6203

    Last Modified: 21 Nov 2024

    SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.

    Published: 10 Mar 2020
    7.2
    High

    CVE-2020-6202

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.

    Published: 10 Mar 2020
    6.1
    Medium

    CVE-2020-6201

    Last Modified: 21 Nov 2024

    The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site Scripting.

    Published: 10 Mar 2020
    5.4
    Medium

    CVE-2020-6200

    Last Modified: 21 Nov 2024

    The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.

    Published: 10 Mar 2020
    5.4
    Medium

    CVE-2020-6199

    Last Modified: 21 Nov 2024

    The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.

    Published: 10 Mar 2020
    9.8
    Critical

    CVE-2020-6198

    Last Modified: 21 Nov 2024

    SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.

    Published: 10 Mar 2020
    3.3
    Low

    CVE-2020-6197

    Last Modified: 21 Nov 2024

    SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.

    Published: 10 Mar 2020
    7.5
    High

    CVE-2020-6196

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads resulting in a Denial of Service.

    Published: 10 Mar 2020
    5.4
    Medium

    CVE-2020-6178

    Last Modified: 21 Nov 2024

    SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.

    Published: 10 Mar 2020
    5.5
    Medium

    CVE-2020-0057

    Last Modified: 21 Nov 2024

    In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141620271

    Published: 10 Mar 2020
    5.5
    Medium

    CVE-2020-0056

    Last Modified: 21 Nov 2024

    In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141619686

    Published: 10 Mar 2020