CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-6068

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

    Published: 14 Feb 2020
    9.8
    Critical

    CVE-2019-4392

    Last Modified: 21 Nov 2024

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

    Published: 14 Feb 2020
    7.5
    High

    CVE-2019-13967

    Last Modified: 21 Nov 2024

    iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI. This only affects the community version.

    Published: 14 Feb 2020
    6.1
    Medium

    CVE-2019-13966

    Last Modified: 21 Nov 2024

    In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).

    Published: 14 Feb 2020
    6.1
    Medium

    CVE-2019-13965

    Last Modified: 21 Nov 2024

    Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.

    Published: 14 Feb 2020
    9.8
    Critical

    CVE-2013-4211

    Last Modified: 21 Nov 2024

    A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

    Published: 14 Feb 2020
    5.4
    Medium

    CVE-2020-8594

    Last Modified: 21 Nov 2024

    The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].

    Published: 14 Feb 2020
    7.4
    High

    CVE-2020-8843

    Last Modified: 21 Nov 2024

    An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy selectively applies to a source equal to ingress. To exploit this vulnerability, someone has to encode a source.uid in this header. This feature is disabled by default in Istio 1.3 and 1.4.

    Published: 14 Feb 2020
    9
    Critical

    CVE-2020-8612

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

    Published: 14 Feb 2020
    8.8
    High

    CVE-2020-8611

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or destroy database elements.

    Published: 14 Feb 2020
    8.1
    High

    CVE-2019-11215

    Last Modified: 21 Nov 2024

    In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the file from the web interface leaves the file writable (can be triggered with XSS); a race condition can be triggered by the hub-connector module (community version only from 2.4.1 to 2.6.0); or editing the file in a CLI.

    Published: 14 Feb 2020
    4.8
    Medium

    CVE-2019-6195

    Last Modified: 21 Nov 2024

    An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.

    Published: 14 Feb 2020
    5.7
    Medium

    CVE-2019-6194

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.

    Published: 14 Feb 2020
    7.5
    High

    CVE-2019-6193

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

    Published: 14 Feb 2020
    5
    Medium

    CVE-2019-6190

    Last Modified: 21 Nov 2024

    Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.

    Published: 14 Feb 2020
    —
    Unknown

    CVE-2019-19763

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 14 Feb 2020
    —
    Unknown

    CVE-2019-19764

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 14 Feb 2020
    —
    Unknown

    CVE-2019-19765

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 14 Feb 2020
    6.1
    Medium

    CVE-2019-19758

    Last Modified: 21 Nov 2024

    A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.

    Published: 14 Feb 2020
    —
    Unknown

    CVE-2019-19762

    Last Modified: 7 Nov 2023

    Unused CVE for 2019

    Published: 14 Feb 2020
    5.4
    Medium

    CVE-2019-19757

    Last Modified: 21 Nov 2024

    An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

    Published: 14 Feb 2020
    7.5
    High

    CVE-2019-19879

    Last Modified: 21 Nov 2024

    HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.

    Published: 14 Feb 2020
    7.5
    High

    CVE-2019-20045

    Last Modified: 21 Nov 2024

    The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active authentic connections or reboot of device. This is a different issue than CVE-2019-16879 and CVE-2019-20046.

    Published: 14 Feb 2020
    9.8
    Critical

    CVE-2019-20046

    Last Modified: 21 Nov 2024

    The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is a different issue than CVE-2019-16879 and CVE-2019-20045.

    Published: 14 Feb 2020
    4.3
    Medium

    CVE-2018-21032

    Last Modified: 21 Nov 2024

    A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager.

    Published: 14 Feb 2020
    6.5
    Medium

    CVE-2018-21033

    Last Modified: 21 Nov 2024

    A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.

    Published: 14 Feb 2020
    5.9
    Medium

    CVE-2019-20455

    Last Modified: 21 Nov 2024

    Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.

    Published: 14 Feb 2020
    5
    Medium

    CVE-2020-7251

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from older versions of ENS.

    Published: 14 Feb 2020
    4.3
    Medium

    CVE-2020-5532

    Last Modified: 21 Nov 2024

    ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.

    Published: 14 Feb 2020
    4.2
    Medium

    CVE-2020-1732

    Last Modified: 21 Nov 2024

    A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.

    Published: 14 Feb 2020
    6.5
    Medium

    CVE-2020-3862

    Last Modified: 21 Nov 2024

    A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.

    Published: 14 Feb 2020
    8.8
    High

    CVE-2020-3865

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 14 Feb 2020
    8.8
    High

    CVE-2020-3868

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 14 Feb 2020
    7.5
    High

    CVE-2020-8131

    Last Modified: 21 Nov 2024

    Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

    Published: 14 Feb 2020
    7.8
    High

    CVE-2020-3864

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.

    Published: 14 Feb 2020
    9.8
    Critical

    CVE-2016-2338

    Last Modified: 21 Nov 2024

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

    Published: 14 Feb 2020
    6.1
    Medium

    CVE-2020-3867

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 14 Feb 2020
    5.4
    Medium

    CVE-2013-4791

    Last Modified: 21 Nov 2024

    PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2013-4792

    Last Modified: 21 Nov 2024

    PrestaShop before 1.4.11 allows logout CSRF.

    Published: 13 Feb 2020
    6.1
    Medium

    CVE-2013-5212

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2013-5687

    Last Modified: 21 Nov 2024

    RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2013-6277

    Last Modified: 21 Nov 2024

    QNAP VioCard 300 has hardcoded RSA private keys.

    Published: 13 Feb 2020
    7.5
    High

    CVE-2013-6360

    Last Modified: 21 Nov 2024

    TRENDnet TS-S402 has a backdoor to enable TELNET.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-6362

    Last Modified: 21 Nov 2024

    Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

    Published: 13 Feb 2020
    5.5
    Medium

    CVE-2013-6927

    Last Modified: 21 Nov 2024

    Internet TRiLOGI Server (unknown versions) could allow a local user to bypass security and create a local user account.

    Published: 13 Feb 2020
    9.8
    Critical

    CVE-2013-7098

    Last Modified: 21 Nov 2024

    OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.

    Published: 13 Feb 2020
    8.8
    High

    CVE-2020-8858

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9552.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8856

    Last Modified: 21 Nov 2024

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of watermarks. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9640.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8857

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of form Annotation objects within AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9862.

    Published: 13 Feb 2020
    7.8
    High

    CVE-2020-8854

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of JPEG files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9606.

    Published: 13 Feb 2020