CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2019-12954

    Last Modified: 21 Nov 2024

    SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.

    Published: 17 Feb 2020
    —
    Unknown

    CVE-2015-1387

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1454. Reason: This candidate is a reservation duplicate of CVE-2015-1454. Notes: All CVE users should reference CVE-2015-1454 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Feb 2020
    7.5
    High

    CVE-2013-3722

    Last Modified: 21 Nov 2024

    A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2013-3738

    Last Modified: 21 Nov 2024

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

    Published: 17 Feb 2020
    5.4
    Medium

    CVE-2020-9038

    Last Modified: 21 Nov 2024

    Joplin through 1.0.184 allows Arbitrary File Read via XSS.

    Published: 17 Feb 2020
    8.1
    High

    CVE-2020-1692

    Last Modified: 21 Nov 2024

    Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

    Published: 17 Feb 2020
    6.1
    Medium

    CVE-2020-6850

    Last Modified: 21 Nov 2024

    Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-8427

    Last Modified: 21 Nov 2024

    In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-8518

    Last Modified: 21 Nov 2024

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

    Published: 17 Feb 2020
    7.5
    High

    CVE-2020-8795

    Last Modified: 21 Nov 2024

    In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9006

    Last Modified: 21 Nov 2024

    The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on Wordpress instances. (This issue has been fixed in the 3.x branch of popup-builder.)

    Published: 17 Feb 2020
    4.3
    Medium

    CVE-2019-12825

    Last Modified: 21 Nov 2024

    Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other words, authenticated remote attackers can read Docker registries of other groups. When a legitimate user changes the path of a group, Docker registries are not adapted, leaving them in the old namespace. They are not protected and are available to all other users with no previous access to the repo.

    Published: 17 Feb 2020
    7.8
    High

    CVE-2020-9005

    Last Modified: 21 Nov 2024

    meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-5531

    Last Modified: 21 Nov 2024

    Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number 21121 or before), MELSEC iQ-R Series C Controller Module / C Intelligent Function Module(R12CCPU-V Ethernet port (CH1, CH2): First 2 digits of serial number 11 or before, and RD55UP06-V Ethernet port: First 2 digits of serial number 08 or before), and MELIPC Series MI5000(MI5122-VW Ethernet port (CH1): First 2 digits of serial number 03 or before, or the firmware version 03 or before) allow remote attackers to cause a denial of service and/or malware being executed via unspecified vectors.

    Published: 17 Feb 2020
    4.2
    Medium

    CVE-2020-7252

    Last Modified: 21 Nov 2024

    Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9020

    Last Modified: 21 Nov 2024

    Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9021

    Last Modified: 21 Nov 2024

    Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.

    Published: 17 Feb 2020
    6.1
    Medium

    CVE-2020-9022

    Last Modified: 21 Nov 2024

    An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9023

    Last Modified: 21 Nov 2024

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9024

    Last Modified: 21 Nov 2024

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.

    Published: 17 Feb 2020
    6.1
    Medium

    CVE-2020-9025

    Last Modified: 21 Nov 2024

    Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9026

    Last Modified: 21 Nov 2024

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.

    Published: 17 Feb 2020
    9.8
    Critical

    CVE-2020-9027

    Last Modified: 21 Nov 2024

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.

    Published: 17 Feb 2020
    6.1
    Medium

    CVE-2020-9028

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).

    Published: 17 Feb 2020
    6.5
    Medium

    CVE-2020-9029

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.

    Published: 17 Feb 2020
    6.5
    Medium

    CVE-2020-9030

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.

    Published: 17 Feb 2020
    6.5
    Medium

    CVE-2020-9031

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.

    Published: 17 Feb 2020
    6.5
    Medium

    CVE-2020-9032

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.

    Published: 17 Feb 2020
    6.5
    Medium

    CVE-2020-9033

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.

    Published: 17 Feb 2020
    7.5
    High

    CVE-2020-9034

    Last Modified: 21 Nov 2024

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.

    Published: 17 Feb 2020
    5.5
    Medium

    CVE-2020-12767

    Last Modified: 21 Nov 2024

    exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.

    Published: 17 Feb 2020
    7.5
    High

    CVE-2019-10790

    Last Modified: 21 Nov 2024

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB. However, it is found that the internal index can be forged by adding additional properties into user-input. If index is found in the query, taffyDB will ignore other query conditions and directly return the indexed data item. Moreover, the internal index is in an easily-guessable format (e.g., T000002R000001). As such, attackers can use this vulnerability to access any data items in the DB.

    Published: 17 Feb 2020
    5.4
    Medium

    CVE-2020-9016

    Last Modified: 21 Nov 2024

    Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

    Published: 16 Feb 2020
    4.3
    Medium

    CVE-2020-9013

    Last Modified: 21 Nov 2024

    Arvato Skillpipe 3.0 allows attackers to bypass intended print restrictions by deleting <div id="watermark"> from the HTML source code.

    Published: 16 Feb 2020
    6.1
    Medium

    CVE-2020-9012

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

    Published: 16 Feb 2020
    5.4
    Medium

    CVE-2020-9007

    Last Modified: 21 Nov 2024

    Codoforum 4.8.8 allows self-XSS via the title of a new topic.

    Published: 16 Feb 2020
    7.8
    High

    CVE-2019-20456

    Last Modified: 21 Nov 2024

    Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

    Published: 16 Feb 2020
    8.8
    High

    CVE-2020-8997

    Last Modified: 21 Nov 2024

    Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced in October 2018).

    Published: 16 Feb 2020
    4.3
    Medium

    CVE-2020-8996

    Last Modified: 21 Nov 2024

    AnyShare Cloud 6.0.9 allows authenticated directory traversal to read files, as demonstrated by the interface/downloadwithpath/downloadfile/?filepath=/etc/passwd URI.

    Published: 16 Feb 2020
    6.5
    Medium

    CVE-2019-14587

    Last Modified: 21 Nov 2024

    Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 16 Feb 2020
    5.7
    Medium

    CVE-2019-14558

    Last Modified: 21 Nov 2024

    Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 16 Feb 2020
    8
    High

    CVE-2019-14586

    Last Modified: 21 Nov 2024

    Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

    Published: 16 Feb 2020
    7.8
    High

    CVE-2019-20044

    Last Modified: 21 Nov 2024

    In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

    Published: 16 Feb 2020
    5.4
    Medium

    CVE-2020-7050

    Last Modified: 21 Nov 2024

    Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.

    Published: 15 Feb 2020
    6.5
    Medium

    CVE-2023-0459

    Last Modified: 21 Nov 2024

    Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47

    Published: 15 Feb 2020
    9.8
    Critical

    CVE-2020-8128

    Last Modified: 21 Nov 2024

    An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

    Published: 14 Feb 2020
    4.3
    Medium

    CVE-2019-15594

    Last Modified: 21 Nov 2024

    GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via the merge request endpoint.

    Published: 14 Feb 2020
    9.8
    Critical

    CVE-2020-8129

    Last Modified: 21 Nov 2024

    An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.

    Published: 14 Feb 2020
    4.3
    Medium

    CVE-2019-15592

    Last Modified: 21 Nov 2024

    GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge request ID associated to an issue via the activity timeline.

    Published: 14 Feb 2020
    8.8
    High

    CVE-2019-5187

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 14 Feb 2020