CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-19134

    Last Modified: 21 Nov 2024

    The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index.php p parameter because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to inject HTML or arbitrary JavaScript within the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based tokens or to launch other attacks.

    Published: 26 Feb 2020
    6.5
    Medium

    CVE-2020-9337

    Last Modified: 21 Nov 2024

    In GolfBuddy Course Manager 1.1, passwords are sent (with base64 encoding) via a GET request.

    Published: 26 Feb 2020
    5.9
    Medium

    CVE-2019-15608

    Last Modified: 21 Nov 2024

    The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

    Published: 26 Feb 2020
    6.5
    Medium

    CVE-2020-5405

    Last Modified: 21 Nov 2024

    Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a directory traversal attack.

    Published: 26 Feb 2020
    6.1
    Medium

    CVE-2020-29565

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.

    Published: 26 Feb 2020
    7.5
    High

    CVE-2020-9431

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operations.

    Published: 26 Feb 2020
    8.6
    High

    CVE-2020-1745

    Last Modified: 21 Nov 2024

    A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution.

    Published: 26 Feb 2020
    8.8
    High

    CVE-2020-6407

    Last Modified: 21 Nov 2024

    Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 26 Feb 2020
    7.5
    High

    CVE-2020-9428

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.

    Published: 26 Feb 2020
    7.5
    High

    CVE-2020-9430

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field.

    Published: 26 Feb 2020
    7.8
    High

    CVE-2019-4000

    Last Modified: 21 Nov 2024

    Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.

    Published: 25 Feb 2020
    9.8
    Critical

    CVE-2020-9398

    Last Modified: 21 Nov 2024

    ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

    Published: 25 Feb 2020
    10
    Critical

    CVE-2015-0565

    Last Modified: 21 Nov 2024

    NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

    Published: 25 Feb 2020
    8.1
    High

    CVE-2020-8809

    Last Modified: 21 Nov 2024

    Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and gurux.fi/updates/updates.xml. Then, the attacker can modify the contents of downloaded files. In the case of add-ins (if the user is using those), this will lead to code execution. In case of OBIS codes (which the user is always using as they are needed to communicate with the energy meters), this can lead to code execution when combined with CVE-2020-8810.

    Published: 25 Feb 2020
    8.1
    High

    CVE-2020-8810

    Last Modified: 21 Nov 2024

    An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable files and place them in an autorun directory, or to place DLLs inside the existing GXDLMS Director installation (run on next execution of GXDLMS Director). This can be used to achieve code execution even if the user doesn't have any add-ins installed.

    Published: 25 Feb 2020
    6.5
    Medium

    CVE-2020-9379

    Last Modified: 21 Nov 2024

    The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow unauthorized access to user conversations.

    Published: 25 Feb 2020
    7.8
    High

    CVE-2019-3999

    Last Modified: 21 Nov 2024

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2020-9394

    Last Modified: 21 Nov 2024

    An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

    Published: 25 Feb 2020
    6.1
    Medium

    CVE-2020-9393

    Last Modified: 21 Nov 2024

    An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.

    Published: 25 Feb 2020
    5.4
    Medium

    CVE-2020-9008

    Last Modified: 21 Nov 2024

    Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.

    Published: 25 Feb 2020
    6.1
    Medium

    CVE-2020-9019

    Last Modified: 21 Nov 2024

    The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.

    Published: 25 Feb 2020
    5.3
    Medium

    CVE-2020-9018

    Last Modified: 21 Nov 2024

    LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.

    Published: 25 Feb 2020
    8
    High

    CVE-2020-9017

    Last Modified: 21 Nov 2024

    LiteCart through 2.2.1 allows CSV injection via a customer's profile.

    Published: 25 Feb 2020
    4.8
    Medium

    CVE-2019-12863

    Last Modified: 21 Nov 2024

    SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.

    Published: 25 Feb 2020
    5.4
    Medium

    CVE-2020-9334

    Last Modified: 21 Nov 2024

    A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.

    Published: 25 Feb 2020
    9.8
    Critical

    CVE-2020-8794

    Last Modified: 21 Nov 2024

    OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

    Published: 25 Feb 2020
    4.8
    Medium

    CVE-2020-9335

    Last Modified: 21 Nov 2024

    Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.

    Published: 25 Feb 2020
    4.7
    Medium

    CVE-2020-8793

    Last Modified: 21 Nov 2024

    OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.

    Published: 25 Feb 2020
    7.1
    High

    CVE-2019-5139

    Last Modified: 21 Nov 2024

    An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5143

    Last Modified: 21 Nov 2024

    An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    7.5
    High

    CVE-2019-5148

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.

    Published: 25 Feb 2020
    7.2
    High

    CVE-2019-5165

    Last Modified: 21 Nov 2024

    An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5153

    Last Modified: 21 Nov 2024

    An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5162

    Last Modified: 21 Nov 2024

    An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    7.5
    High

    CVE-2019-5137

    Last Modified: 21 Nov 2024

    The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

    Published: 25 Feb 2020
    9.9
    Critical

    CVE-2019-5138

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5136

    Last Modified: 21 Nov 2024

    An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    7.2
    High

    CVE-2019-5142

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5141

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2019-5140

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

    Published: 25 Feb 2020
    5.3
    Medium

    CVE-2019-4672

    Last Modified: 21 Nov 2024

    IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.

    Published: 25 Feb 2020
    7.5
    High

    CVE-2019-4557

    Last Modified: 21 Nov 2024

    IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.

    Published: 25 Feb 2020
    8.1
    High

    CVE-2020-8818

    Last Modified: 21 Nov 2024

    An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

    Published: 25 Feb 2020
    8.1
    High

    CVE-2020-8819

    Last Modified: 21 Nov 2024

    An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.) and therefore bypass the payment process (e.g., spoof an order status by manually sending an IPN callback request with a valid signature but without real payment) and/or receive all of the subsequent payments.

    Published: 25 Feb 2020
    8.8
    High

    CVE-2020-10531

    Last Modified: 21 Nov 2024

    An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

    Published: 25 Feb 2020
    9.1
    Critical

    CVE-2020-36330

    Last Modified: 21 Nov 2024

    A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

    Published: 25 Feb 2020
    5.5
    Medium

    CVE-2020-9391

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Library malloc implementation.

    Published: 25 Feb 2020
    9.1
    Critical

    CVE-2020-1731

    Last Modified: 21 Nov 2024

    A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password when installing Keycloak, however the password remains the same when deployed to the same OpenShift namespace.

    Published: 25 Feb 2020
    9.8
    Critical

    CVE-2020-36328

    Last Modified: 21 Nov 2024

    A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Feb 2020
    6.1
    Medium

    CVE-2020-9405

    Last Modified: 21 Nov 2024

    IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.

    Published: 25 Feb 2020