CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-8439

    Last Modified: 21 Nov 2024

    Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to the users/21/edit URI.

    Published: 7 Mar 2020
    7.8
    High

    CVE-2020-9470

    Last Modified: 21 Nov 2024

    An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These cookies may be used to hijack user and administrative sessions, including the ability to execute Lua commands as root within the administration panel.

    Published: 7 Mar 2020
    6.1
    Medium

    CVE-2020-9281

    Last Modified: 25 Aug 2026

    A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

    Published: 7 Mar 2020
    —
    Unknown

    CVE-2020-10020

    Last Modified: 7 Nov 2023

    Number assigned to issue that does not qualify for a CVE

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14508

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14506

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14507

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14503

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14504

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14505

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14501

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14502

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14499

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2019-14500

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14208

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14206

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14207

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14205

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14203

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2017-14204

    Last Modified: 7 Nov 2023

    Unused CVE for 2017

    Published: 6 Mar 2020
    7.8
    High

    CVE-2020-8634

    Last Modified: 21 Nov 2024

    Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.

    Published: 6 Mar 2020
    7.8
    High

    CVE-2020-8635

    Last Modified: 21 Nov 2024

    Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.

    Published: 6 Mar 2020
    9.8
    Critical

    CVE-2020-10212

    Last Modified: 21 Nov 2024

    upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an attacker could create a DNS hostname that resolves to the 0.0.0.0 IP address for DNS pinning. NOTE: this issue exists because of an incomplete fix for CVE-2018-14728.

    Published: 6 Mar 2020
    5.4
    Medium

    CVE-2019-19772

    Last Modified: 21 Nov 2024

    Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

    Published: 6 Mar 2020
    5.4
    Medium

    CVE-2019-19773

    Last Modified: 21 Nov 2024

    Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

    Published: 6 Mar 2020
    5.4
    Medium

    CVE-2020-10112

    Last Modified: 21 Nov 2024

    Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not change based on parameter values. All other data traffic going through Citrix Gateway are NOT cached by default

    Published: 6 Mar 2020
    7.5
    High

    CVE-2020-10111

    Last Modified: 21 Nov 2024

    Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization

    Published: 6 Mar 2020
    5.3
    Medium

    CVE-2020-10110

    Last Modified: 21 Nov 2024

    Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request or a response. The "Age" header provides the age of the cached response in seconds. Both headers are commonly used for proxy cache and the information is not sensitive

    Published: 6 Mar 2020
    9.8
    Critical

    CVE-2020-5328

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions prior to 8.2.0 contain an unauthorized access vulnerability due to a lack of thorough authorization checks when SyncIQ is licensed, but encrypted syncs are not marked as required. When this happens, loss of control of the cluster can occur.

    Published: 6 Mar 2020
    8.1
    High

    CVE-2020-5327

    Last Modified: 21 Nov 2024

    Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

    Published: 6 Mar 2020
    7.5
    High

    CVE-2020-10193

    Last Modified: 21 Nov 2024

    ESET Archive Support Module before 1294 allows virus-detection bypass via crafted RAR Compression Information in an archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS), Cyber Security (macOS), Mobile Security for Android, Smart TV Security, and NOD32 Antivirus 4 for Linux Desktop.

    Published: 6 Mar 2020
    8.8
    High

    CVE-2020-9458

    Last Modified: 21 Nov 2024

    In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php rm_form_export.

    Published: 6 Mar 2020
    8.8
    High

    CVE-2020-9457

    Last Modified: 21 Nov 2024

    The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.

    Published: 6 Mar 2020
    8.8
    High

    CVE-2020-9456

    Last Modified: 21 Nov 2024

    In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.

    Published: 6 Mar 2020
    4.3
    Medium

    CVE-2020-9455

    Last Modified: 21 Nov 2024

    The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.

    Published: 6 Mar 2020
    8.8
    High

    CVE-2020-9454

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.

    Published: 6 Mar 2020
    9.8
    Critical

    CVE-2020-8113

    Last Modified: 21 Nov 2024

    GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.

    Published: 6 Mar 2020
    7.3
    High

    CVE-2020-9531

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are read and executed. After reading the resource files, relevant components open the link of the incoming URL. Although the URL is safe and can pass security detection, the data carried in the parameters are loaded and executed. An attacker can use NFC tools to get close enough to a user's unlocked phone to cause apps to be installed and information to be leaked. This is fixed on version: 2001122.

    Published: 6 Mar 2020
    6.5
    Medium

    CVE-2020-9530

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of opening other components. Attackers need to induce users to open specific web pages in a specific network environment. By jumping to the WebView component of Messaging(com.android.MMS) and loading malicious web pages, information leakage can occur. This is fixed on version: 2001122; 11.0.1.54.

    Published: 6 Mar 2020
    9.8
    Critical

    CVE-2020-10189

    Last Modified: 7 Nov 2025

    Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

    Published: 6 Mar 2020
    7.8
    High

    CVE-2020-9756

    Last Modified: 21 Nov 2024

    Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control. The IOCTL Codes 0x80102050 and 0x80102054 allows a local user with low privileges to read/write 1/2/4 bytes from or to an IO port. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    Published: 6 Mar 2020
    —
    Unknown

    CVE-2020-7975

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 6 Mar 2020
    6.5
    Medium

    CVE-2019-20503

    Last Modified: 21 Nov 2024

    usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

    Published: 6 Mar 2020
    7.5
    High

    CVE-2020-7212

    Last Modified: 21 Nov 2024

    The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).

    Published: 6 Mar 2020
    7.5
    High

    CVE-2020-10184

    Last Modified: 21 Nov 2024

    The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.

    Published: 5 Mar 2020
    8.6
    High

    CVE-2020-10185

    Last Modified: 21 Nov 2024

    The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.

    Published: 5 Mar 2020
    7.5
    High

    CVE-2020-6986

    Last Modified: 2 Jun 2026

    In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.

    Published: 5 Mar 2020
    7.8
    High

    CVE-2020-6971

    Last Modified: 21 Nov 2024

    In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.

    Published: 5 Mar 2020
    7.8
    High

    CVE-2020-5957

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

    Published: 5 Mar 2020
    7.5
    High

    CVE-2019-17646

    Last Modified: 21 Nov 2024

    An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.

    Published: 5 Mar 2020