CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2018-19284

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 2 Mar 2020
    —
    Unknown

    CVE-2018-18479

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2018-16357

    Last Modified: 21 Nov 2024

    An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2018-16356

    Last Modified: 21 Nov 2024

    An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2020-8437

    Last Modified: 21 Nov 2024

    The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.

    Published: 2 Mar 2020
    5.4
    Medium

    CVE-2020-8778

    Last Modified: 21 Nov 2024

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.

    Published: 2 Mar 2020
    5.4
    Medium

    CVE-2020-8777

    Last Modified: 21 Nov 2024

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.

    Published: 2 Mar 2020
    5.4
    Medium

    CVE-2020-8776

    Last Modified: 21 Nov 2024

    Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.

    Published: 2 Mar 2020
    6.1
    Medium

    CVE-2018-15820

    Last Modified: 21 Nov 2024

    EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2018-15819

    Last Modified: 21 Nov 2024

    EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2019-19608

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the registeredList.cgi page. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2019-19607

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.

    Published: 2 Mar 2020
    6.1
    Medium

    CVE-2019-19371

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the join meeting interface. A successful exploit could allow an attacker to execute arbitrary scripts.

    Published: 2 Mar 2020
    6.1
    Medium

    CVE-2019-19370

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the file upload interface. A successful exploit could allow an attacker to execute arbitrary scripts.

    Published: 2 Mar 2020
    5.9
    Medium

    CVE-2019-18863

    Last Modified: 21 Nov 2024

    A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2019-18903

    Last Modified: 21 Nov 2024

    A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-28.26.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.9.1. openSUSE Factory wicked versions prior to 0.6.62.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2019-18902

    Last Modified: 21 Nov 2024

    A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise Server 15 wicked versions prior to 0.6.60-3.21.1. openSUSE Leap 15.1 wicked versions prior to 0.6.60-lp151.2.6.1. openSUSE Factory wicked versions prior to 0.6.62.

    Published: 2 Mar 2020
    2.2
    Low

    CVE-2020-8013

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers on default systems, so exploitation is difficult. This issue affects: SUSE Linux Enterprise Server 12 permissions versions prior to 2015.09.28.1626-17.27.1. SUSE Linux Enterprise Server 15 permissions versions prior to 20181116-9.23.1. SUSE Linux Enterprise Server 11 permissions versions prior to 2013.1.7-0.6.12.1.

    Published: 2 Mar 2020
    4.8
    Medium

    CVE-2018-14384

    Last Modified: 21 Nov 2024

    The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.

    Published: 2 Mar 2020
    5.1
    Medium

    CVE-2019-18901

    Last Modified: 21 Nov 2024

    A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb versions prior to 10.2.31-3.25.1. SUSE Linux Enterprise Server 15 mariadb versions prior to 10.2.31-3.26.1.

    Published: 2 Mar 2020
    —
    Unknown

    CVE-2018-11675

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Mar 2020
    7.8
    High

    CVE-2017-12580

    Last Modified: 21 Nov 2024

    An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the installer EXE is executed by the user, the DLL located in the EXE's current directory will be loaded instead of the Windows DLL, allowing the attacker to run arbitrary code on the affected system.

    Published: 2 Mar 2020
    8.8
    High

    CVE-2015-1583

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.

    Published: 2 Mar 2020
    —
    Unknown

    CVE-2020-6764

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Mar 2020
    7.5
    High

    CVE-2019-12183

    Last Modified: 21 Nov 2024

    Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.

    Published: 2 Mar 2020
    6.1
    Medium

    CVE-2019-20486

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2019-20488

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated by shell metacharacters in the sysDNSHost parameter.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2019-20489

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentication bypass and other problems that ultimately allow an attacker to remotely compromise the device from a malicious webpage. The attacker sends an FW_remote.htm&todo=cfg_init request without a cookie, reads the Set-Cookie header in the 401 Unauthorized response, and then repeats the FW_remote.htm&todo=cfg_init request with the specified cookie.

    Published: 2 Mar 2020
    8.8
    High

    CVE-2019-20487

    Last Modified: 21 Nov 2024

    An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI.

    Published: 2 Mar 2020
    7.2
    High

    CVE-2020-8500

    Last Modified: 21 Nov 2024

    In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality

    Published: 2 Mar 2020
    5.3
    Medium

    CVE-2020-4292

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 uses a cross-domain policy file that includes domains that should not be trusted which could disclose sensitive information. IBM X-Force ID: 176335.

    Published: 2 Mar 2020
    8.6
    High

    CVE-2020-4283

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 176206.

    Published: 2 Mar 2020
    8.8
    High

    CVE-2018-17058

    Last Modified: 21 Nov 2024

    An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.

    Published: 2 Mar 2020
    6.5
    Medium

    CVE-2020-5539

    Last Modified: 21 Nov 2024

    GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and then alter or disclose the information via unspecified vectors.

    Published: 2 Mar 2020
    7.8
    High

    CVE-2020-9549

    Last Modified: 21 Nov 2024

    In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2020-9545

    Last Modified: 21 Nov 2024

    Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2020-9548

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2020-9546

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

    Published: 2 Mar 2020
    8.1
    High

    CVE-2020-6096

    Last Modified: 13 Feb 2026

    An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data.

    Published: 2 Mar 2020
    5.5
    Medium

    CVE-2023-3745

    Last Modified: 20 Nov 2025

    A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.

    Published: 2 Mar 2020
    7.5
    High

    CVE-2020-0034

    Last Modified: 21 Nov 2024

    In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1Android ID: A-62458770

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2020-10018

    Last Modified: 21 Nov 2024

    WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

    Published: 2 Mar 2020
    5.5
    Medium

    CVE-2020-12655

    Last Modified: 21 Nov 2024

    An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive duration via an XFS v5 image with crafted metadata, aka CID-d0c7feaf8767.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2020-1747

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.

    Published: 2 Mar 2020
    9.8
    Critical

    CVE-2020-9547

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).

    Published: 2 Mar 2020
    5.3
    Medium

    CVE-2020-10960

    Last Modified: 21 Nov 2024

    In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows applying an event handler to any Cascading Style Sheets (CSS) selector. There is no known way to exploit this for cross-site scripting (XSS).

    Published: 2 Mar 2020
    6.5
    Medium

    CVE-2020-5249

    Last Modified: 21 Nov 2024

    In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carriage return character to end the header and inject malicious content, such as additional headers or an entirely new response body. This vulnerability is known as HTTP Response Splitting. While not an attack in itself, response splitting is a vector for several other attacks, such as cross-site scripting (XSS). This is related to CVE-2020-5247, which fixed this vulnerability but only for regular responses. This has been fixed in 4.3.3 and 3.12.4.

    Published: 2 Mar 2020
    7.8
    High

    CVE-2020-9540

    Last Modified: 21 Nov 2024

    Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.

    Published: 1 Mar 2020
    8.8
    High

    CVE-2020-9534

    Last Modified: 21 Nov 2024

    fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.

    Published: 1 Mar 2020
    8.8
    High

    CVE-2020-9535

    Last Modified: 21 Nov 2024

    fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malformed.

    Published: 1 Mar 2020