CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-9406

    Last Modified: 21 Nov 2024

    IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

    Published: 25 Feb 2020
    9.8
    Critical

    CVE-2020-36329

    Last Modified: 21 Nov 2024

    A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Feb 2020
    7.5
    High

    CVE-2020-36332

    Last Modified: 21 Nov 2024

    A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

    Published: 25 Feb 2020
    5.3
    Medium

    CVE-2020-9407

    Last Modified: 21 Nov 2024

    IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.

    Published: 25 Feb 2020
    7.5
    High

    CVE-2020-9385

    Last Modified: 21 Nov 2024

    A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode generation.

    Published: 24 Feb 2020
    5.4
    Medium

    CVE-2020-9382

    Last Modified: 21 Nov 2024

    An issue was discovered in the Widgets extension through 1.4.0 for MediaWiki. Improper title sanitization allowed for the execution of any wiki page as a widget (as defined by this extension) via MediaWiki's {{#widget:}} parser function.

    Published: 24 Feb 2020
    7.5
    High

    CVE-2020-9381

    Last Modified: 21 Nov 2024

    controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.

    Published: 24 Feb 2020
    8.8
    High

    CVE-2020-1937

    Last Modified: 21 Nov 2024

    Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-9374

    Last Modified: 21 Nov 2024

    On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

    Published: 24 Feb 2020
    6.1
    Medium

    CVE-2019-17229

    Last Modified: 21 Nov 2024

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.

    Published: 24 Feb 2020
    6.5
    Medium

    CVE-2019-17228

    Last Modified: 21 Nov 2024

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

    Published: 24 Feb 2020
    6.1
    Medium

    CVE-2019-12513

    Last Modified: 21 Nov 2024

    In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname field, an attacker may execute stored XSS attacks against this device. When the malicious DHCP request is received, the device will generate a log entry containing the malicious hostname. This log entry may then be viewed at Advanced settings->Administration->Logs to trigger the exploit. Although this value is inserted into a textarea tag, converted to all-caps, and limited in length, attacks are still possible.

    Published: 24 Feb 2020
    6.1
    Medium

    CVE-2019-12512

    Last Modified: 21 Nov 2024

    In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by supplying a malicious X-Forwarded-For header while performing an incorrect login attempt. The value supplied by this header will be inserted into administrative logs, found at Advanced settings->Administration->Logs, and may trigger when the page is viewed. Although this value is inserted into a textarea tag, the attack simply needs to supply a closing textarea tag.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2019-12511

    Last Modified: 21 Nov 2024

    In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced QoS being enabled, and a valid authentication JWT, additional vulnerabilities (CVE-2019-12510) allow an attacker to interact with the entire SOAP API without authentication. Additionally, DNS rebinding techniques may be used to exploit this vulnerability remotely. Exploiting this vulnerability is somewhat involved. The following limitations apply to the payload and must be overcome for successful exploitation: - No more than 17 characters may be used. - At least one colon must be included to prevent mangling. - A single-quote and meta-character must be used to break out of the existing command. - Parent command remnants after the injection point must be dealt with. - The payload must be in all-caps. Despite these limitations, it is still possible to gain access to an interactive root shell via this vulnerability. Since the web server assigns certain HTTP headers to environment variables with all-caps names, it is possible to insert a payload into one such header and reference the subsequent environment variable in the injection point.

    Published: 24 Feb 2020
    9.1
    Critical

    CVE-2019-12510

    Last Modified: 21 Nov 2024

    In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of the device's settings and view various configuration settings.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2018-14705

    Last Modified: 21 Nov 2024

    In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses severe risks to the confidentiality and integrity of data stored within the applications and the device itself.

    Published: 24 Feb 2020
    6.5
    Medium

    CVE-2018-13313

    Last Modified: 21 Nov 2024

    In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user knows their current password before allowing them to change their password. However, this JavaScript contains the current user’s password in plaintext.

    Published: 24 Feb 2020
    5.8
    Medium

    CVE-2020-2732

    Last Modified: 21 Nov 2024

    A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest.

    Published: 24 Feb 2020
    8.2
    High

    CVE-2019-10799

    Last Modified: 21 Nov 2024

    compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2019-10796

    Last Modified: 21 Nov 2024

    rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the arguement of exec function without any sanitization.

    Published: 24 Feb 2020
    5.3
    Medium

    CVE-2019-10798

    Last Modified: 21 Nov 2024

    rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.

    Published: 24 Feb 2020
    7.9
    High

    CVE-2020-5245

    Last Modified: 21 Nov 2024

    Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.

    Published: 24 Feb 2020
    7.5
    High

    CVE-2020-9369

    Last Modified: 21 Nov 2024

    Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

    Published: 24 Feb 2020
    8
    High

    CVE-2020-5244

    Last Modified: 21 Nov 2024

    In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2016-11020

    Last Modified: 21 Nov 2024

    Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

    Published: 24 Feb 2020
    7.5
    High

    CVE-2012-0785

    Last Modified: 21 Nov 2024

    Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

    Published: 24 Feb 2020
    7.5
    High

    CVE-2020-9365

    Last Modified: 21 Nov 2024

    An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-4222

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-4213

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-4212

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-4211

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-4210

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.

    Published: 24 Feb 2020
    4.3
    Medium

    CVE-2019-4745

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.

    Published: 24 Feb 2020
    5.3
    Medium

    CVE-2019-4703

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.

    Published: 24 Feb 2020
    6.1
    Medium

    CVE-2019-4595

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 167878.

    Published: 24 Feb 2020
    7.8
    High

    CVE-2020-9362

    Last Modified: 21 Nov 2024

    The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and Total Security for Android.

    Published: 24 Feb 2020
    7.8
    High

    CVE-2020-9363

    Last Modified: 21 Nov 2024

    The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2019-18182

    Last Modified: 21 Nov 2024

    pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2019-18183

    Last Modified: 21 Nov 2024

    pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta file.

    Published: 24 Feb 2020
    8.8
    High

    CVE-2019-20480

    Last Modified: 21 Nov 2024

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2019-20481

    Last Modified: 21 Nov 2024

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

    Published: 24 Feb 2020
    5.4
    Medium

    CVE-2020-5186

    Last Modified: 21 Nov 2024

    DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).

    Published: 24 Feb 2020
    8.8
    High

    CVE-2020-5187

    Last Modified: 21 Nov 2024

    DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

    Published: 24 Feb 2020
    6.5
    Medium

    CVE-2020-5188

    Last Modified: 21 Nov 2024

    DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

    Published: 24 Feb 2020
    8.8
    High

    CVE-2019-15299

    Last Modified: 21 Nov 2024

    An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.

    Published: 24 Feb 2020
    8
    High

    CVE-2019-3670

    Last Modified: 21 Nov 2024

    Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cross site scripting attack.

    Published: 24 Feb 2020
    4.8
    Medium

    CVE-2020-1935

    Last Modified: 21 Nov 2024

    In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

    Published: 24 Feb 2020
    8.8
    High

    CVE-2020-6418

    Last Modified: 24 Oct 2025

    Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 24 Feb 2020
    6.1
    Medium

    CVE-2020-12137

    Last Modified: 21 Nov 2024

    GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.

    Published: 24 Feb 2020
    8
    High

    CVE-2019-14894

    Last Modified: 21 Nov 2024

    A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on the CloudForms server as root.

    Published: 24 Feb 2020