CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-12426

    Last Modified: 21 Nov 2024

    an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06

    Published: 6 Feb 2020
    7.8
    High

    CVE-2020-7954

    Last Modified: 21 Nov 2024

    An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without the need for a password with sudo.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2020-6855

    Last Modified: 21 Nov 2024

    A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and results in a denial of service.

    Published: 6 Feb 2020
    9.8
    Critical

    CVE-2020-8772

    Last Modified: 21 Nov 2024

    The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

    Published: 6 Feb 2020
    9.8
    Critical

    CVE-2020-8771

    Last Modified: 21 Nov 2024

    The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

    Published: 6 Feb 2020
    7.5
    High

    CVE-2020-7953

    Last Modified: 21 Nov 2024

    An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2020-6856

    Last Modified: 21 Nov 2024

    An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of the XML documents that are used to specify the run-time settings of jobs and orders.

    Published: 6 Feb 2020
    7.7
    High

    CVE-2020-6767

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.

    Published: 6 Feb 2020
    5.3
    Medium

    CVE-2019-19800

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

    Published: 6 Feb 2020
    9.8
    Critical

    CVE-2019-10789

    Last Modified: 21 Nov 2024

    All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

    Published: 6 Feb 2020
    5.9
    Medium

    CVE-2020-5854

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made.

    Published: 6 Feb 2020
    4.3
    Medium

    CVE-2020-5855

    Last Modified: 21 Nov 2024

    When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shell access under unprivileged user.

    Published: 6 Feb 2020
    7.5
    High

    CVE-2020-5856

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0-15.0.1.1 and 14.1.0-14.1.2.2, while processing specifically crafted traffic using the default 'xnet' driver, Virtual Edition instances hosted in Amazon Web Services (AWS) may experience a TMM restart.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2019-16152

    Last Modified: 21 Nov 2024

    A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated.

    Published: 6 Feb 2020
    6.1
    Medium

    CVE-2014-10400

    Last Modified: 21 Nov 2024

    The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

    Published: 6 Feb 2020
    6.1
    Medium

    CVE-2014-10399

    Last Modified: 21 Nov 2024

    The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

    Published: 6 Feb 2020
    6.1
    Medium

    CVE-2014-2875

    Last Modified: 21 Nov 2024

    The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NOTE: CVE-2014-10399 and CVE-2014-10400 were SPLIT from this ID.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2019-17652

    Last Modified: 21 Nov 2024

    A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized.

    Published: 6 Feb 2020
    7.8
    High

    CVE-2019-15711

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root privilege via injecting specially crafted "ExportLogs" type IPC client requests to the fctsched process.

    Published: 6 Feb 2020
    7.5
    High

    CVE-2013-4572

    Last Modified: 21 Nov 2024

    The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

    Published: 6 Feb 2020
    9.8
    Critical

    CVE-2015-2909

    Last Modified: 21 Nov 2024

    Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."

    Published: 6 Feb 2020
    8.8
    High

    CVE-2015-6000

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.

    Published: 6 Feb 2020
    6.1
    Medium

    CVE-2012-2593

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.

    Published: 6 Feb 2020
    7.4
    High

    CVE-2016-9928

    Last Modified: 21 Nov 2024

    MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2010-3917

    Last Modified: 21 Nov 2024

    Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 6 Feb 2020
    6.1
    Medium

    CVE-2020-5528

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Movable Type series (Movable Type 7 r.4603 and earlier (Movable Type 7), Movable Type 6.5.2 and earlier (Movable Type 6.5), Movable Type Advanced 7 r.4603 and earlier (Movable Type Advanced 7), Movable Type Advanced 6.5.2 and earlier (Movable Type Advanced 6.5), Movable Type Premium 1.26 and earlier (Movable Type Premium), and Movable Type Premium Advanced 1.26 and earlier (Movable Type Premium Advanced)) allows remote attackers to inject arbitrary web script or HTML in the block editor and the rich text editor via a specially crafted URL.

    Published: 6 Feb 2020
    7.8
    High

    CVE-2019-20406

    Last Modified: 21 Nov 2024

    The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.

    Published: 6 Feb 2020
    4.3
    Medium

    CVE-2019-20405

    Last Modified: 21 Nov 2024

    The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.

    Published: 6 Feb 2020
    4.3
    Medium

    CVE-2019-20404

    Last Modified: 21 Nov 2024

    The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.

    Published: 6 Feb 2020
    5.3
    Medium

    CVE-2019-20403

    Last Modified: 21 Nov 2024

    The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.

    Published: 6 Feb 2020
    4.9
    Medium

    CVE-2019-20402

    Last Modified: 21 Nov 2024

    Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.

    Published: 6 Feb 2020
    6.5
    Medium

    CVE-2019-20401

    Last Modified: 21 Nov 2024

    Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.

    Published: 6 Feb 2020
    7.8
    High

    CVE-2019-20400

    Last Modified: 21 Nov 2024

    The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.

    Published: 6 Feb 2020
    4.3
    Medium

    CVE-2019-20106

    Last Modified: 21 Nov 2024

    Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.

    Published: 6 Feb 2020
    7.5
    High

    CVE-2019-20104

    Last Modified: 21 Nov 2024

    The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.

    Published: 6 Feb 2020
    8.8
    High

    CVE-2020-8658

    Last Modified: 21 Nov 2024

    The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8673

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8762

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8668

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8686

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8697

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8699

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8724

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8725

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8726

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8727

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8728

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8735

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    —
    Unknown

    CVE-2020-8748

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 6 Feb 2020
    9.8
    Critical

    CVE-2020-9366

    Last Modified: 21 Nov 2024

    A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.

    Published: 6 Feb 2020