CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2019-17569

    Last Modified: 25 Aug 2026

    The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

    Published: 24 Feb 2020
    9.8
    Critical

    CVE-2020-9355

    Last Modified: 21 Nov 2024

    danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.

    Published: 23 Feb 2020
    7.5
    High

    CVE-2020-9354

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal.

    Published: 23 Feb 2020
    5.4
    Medium

    CVE-2020-9350

    Last Modified: 21 Nov 2024

    Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

    Published: 23 Feb 2020
    5.3
    Medium

    CVE-2020-9351

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the _transaction parameter, the server replies with a verbose error showing where the application resides (the absolute path). NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."

    Published: 23 Feb 2020
    9.8
    Critical

    CVE-2020-9352

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."

    Published: 23 Feb 2020
    7.5
    High

    CVE-2020-9353

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) loadFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL is affected by unauthenticated Local File Inclusion via directory-traversal sequences in the elem XML element in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."

    Published: 23 Feb 2020
    9.8
    Critical

    CVE-2020-35527

    Last Modified: 21 Nov 2024

    In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

    Published: 23 Feb 2020
    5.5
    Medium

    CVE-2020-9342

    Last Modified: 21 Nov 2024

    The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.

    Published: 22 Feb 2020
    8.8
    High

    CVE-2020-9341

    Last Modified: 21 Nov 2024

    CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

    Published: 22 Feb 2020
    7.2
    High

    CVE-2020-9340

    Last Modified: 21 Nov 2024

    fauzantrif eLection 2.0 has SQL Injection via the admin/ajax/op_kandidat.php id parameter.

    Published: 22 Feb 2020
    5.4
    Medium

    CVE-2020-9336

    Last Modified: 21 Nov 2024

    fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field.

    Published: 22 Feb 2020
    5.4
    Medium

    CVE-2020-9338

    Last Modified: 21 Nov 2024

    SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.

    Published: 22 Feb 2020
    5.4
    Medium

    CVE-2020-9339

    Last Modified: 21 Nov 2024

    SOPlanning 1.45 allows XSS via the Name or Comment to status.php.

    Published: 22 Feb 2020
    9.8
    Critical

    CVE-2020-9039

    Last Modified: 21 Nov 2024

    Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

    Published: 22 Feb 2020
    8.8
    High

    CVE-2020-8861

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper handling of cookies. An attacker can leverage this vulnerability to execute arbitrary code on the router. Was ZDI-CAN-9554.

    Published: 22 Feb 2020
    8.8
    High

    CVE-2020-8862

    Last Modified: 21 Nov 2024

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from the lack of proper password checking. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-10082.

    Published: 22 Feb 2020
    8
    High

    CVE-2020-8860

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must answer a phone call. The specific flaw exists within the Call Control Setup messages. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the baseband processor. Was ZDI-CAN-9658.

    Published: 22 Feb 2020
    8.8
    High

    CVE-2020-8813

    Last Modified: 21 Nov 2024

    graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

    Published: 22 Feb 2020
    8.8
    High

    CVE-2020-9330

    Last Modified: 21 Nov 2024

    Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.

    Published: 21 Feb 2020
    5.9
    Medium

    CVE-2020-9329

    Last Modified: 21 Nov 2024

    Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.

    Published: 21 Feb 2020
    5
    Medium

    CVE-2019-18846

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.2 allows SSRF.

    Published: 21 Feb 2020
    7.5
    High

    CVE-2020-7907

    Last Modified: 21 Nov 2024

    In the JetBrains Scala plugin before 2019.2.1, some artefact dependencies were resolved over unencrypted connections.

    Published: 21 Feb 2020
    7.8
    High

    CVE-2012-1093

    Last Modified: 21 Nov 2024

    The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.

    Published: 21 Feb 2020
    5.5
    Medium

    CVE-2012-0844

    Last Modified: 21 Nov 2024

    Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

    Published: 21 Feb 2020
    7.8
    High

    CVE-2012-6277

    Last Modified: 21 Nov 2024

    Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."

    Published: 21 Feb 2020
    7.2
    High

    CVE-2020-6842

    Last Modified: 21 Nov 2024

    D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.

    Published: 21 Feb 2020
    6.5
    Medium

    CVE-2013-4088

    Last Modified: 21 Nov 2024

    Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

    Published: 21 Feb 2020
    8.1
    High

    CVE-2012-0063

    Last Modified: 21 Nov 2024

    Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.

    Published: 21 Feb 2020
    6.5
    Medium

    CVE-2013-3551

    Last Modified: 21 Nov 2024

    Kernel/Modules/AgentTicketPhone.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.20, 3.1.x before 3.1.16, and 3.2.x before 3.2.7, and OTRS ITSM 3.0.x before 3.0.8, 3.1.x before 3.1.9, and 3.2.x before 3.2.5 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.

    Published: 21 Feb 2020
    9.8
    Critical

    CVE-2020-6841

    Last Modified: 21 Nov 2024

    D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.

    Published: 21 Feb 2020
    6.1
    Medium

    CVE-2019-19865

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attacker could exploit this by convincing an authenticated user to inject arbitrary JavaScript code in the Profile Name field. A browser would execute this stored XSS payload.

    Published: 21 Feb 2020
    7.5
    High

    CVE-2019-19866

    Last Modified: 21 Nov 2024

    Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive information. By iterating the value of conferenceId to getMailFunction in the JSON API, one can enumerate all conferences scheduled on the platform, with their numbers and access PINs.

    Published: 21 Feb 2020
    6.1
    Medium

    CVE-2020-5326

    Last Modified: 21 Nov 2024

    Affected Dell Client platforms contain a BIOS Setup configuration authentication bypass vulnerability in the pre-boot Intel Rapid Storage Response Technology (iRST) Manager menu. An attacker with physical access to the system could perform unauthorized changes to the BIOS Setup configuration settings without requiring the BIOS Admin password by selecting the Optimized Defaults option in the pre-boot iRST Manager.

    Published: 21 Feb 2020
    7.1
    High

    CVE-2020-5324

    Last Modified: 21 Nov 2024

    Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

    Published: 21 Feb 2020
    7.8
    High

    CVE-2019-19452

    Last Modified: 21 Nov 2024

    A buffer overflow was found in Patriot Viper RGB through 1.1 when processing IoControlCode 0x80102040. Local attackers (including low integrity processes) can exploit this to gain NT AUTHORITY\SYSTEM privileges.

    Published: 21 Feb 2020
    6.1
    Medium

    CVE-2020-5533

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Feb 2020
    8
    High

    CVE-2020-5534

    Last Modified: 21 Nov 2024

    Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.

    Published: 21 Feb 2020
    8.8
    High

    CVE-2020-5524

    Last Modified: 21 Nov 2024

    Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via UPnP function.

    Published: 21 Feb 2020
    8
    High

    CVE-2020-5525

    Last Modified: 21 Nov 2024

    Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via management screen.

    Published: 21 Feb 2020
    8.1
    High

    CVE-2014-7914

    Last Modified: 21 Nov 2024

    btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

    Published: 21 Feb 2020
    9.8
    Critical

    CVE-2016-4606

    Last Modified: 21 Nov 2024

    Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

    Published: 21 Feb 2020
    7.5
    High

    CVE-2020-9327

    Last Modified: 21 Nov 2024

    In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.

    Published: 21 Feb 2020
    5.5
    Medium

    CVE-2020-12768

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.6. svm_cpu_uninit in arch/x86/kvm/svm.c has a memory leak, aka CID-d80b64ff297e. NOTE: third parties dispute this issue because it's a one-time leak at the boot, the size is negligible, and it can't be triggered at will

    Published: 21 Feb 2020
    7.1
    High

    CVE-2020-9383

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.

    Published: 21 Feb 2020
    5.7
    Medium

    CVE-2020-5243

    Last Modified: 21 Nov 2024

    uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings. This has been patched in uap-core 0.7.3.

    Published: 20 Feb 2020
    7.7
    High

    CVE-2020-5242

    Last Modified: 21 Nov 2024

    openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all commands need to be whitelisted in a local file which cannot be changed via REST calls.

    Published: 20 Feb 2020
    4.7
    Medium

    CVE-2019-19694

    Last Modified: 21 Nov 2024

    The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product completely..

    Published: 20 Feb 2020
    7.8
    High

    CVE-2020-8601

    Last Modified: 21 Nov 2024

    Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.

    Published: 20 Feb 2020
    7
    High

    CVE-2019-14688

    Last Modified: 21 Nov 2024

    Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.

    Published: 20 Feb 2020