CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2020-1930

    Last Modified: 21 Nov 2024

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can be injected in a number of scenarios including the same privileges as spamd is run which may be elevated though doing so remotely is difficult. In addition to upgrading to SA 3.4.4, we again recommend that users should only use update channels or 3rd party .cf files from trusted places. If you cannot upgrade, do not use 3rd party rulesets, do not use sa-compile and do not run spamd as an account with elevated privileges.

    Published: 30 Jan 2020
    7.1
    High

    CVE-2020-8648

    Last Modified: 21 Nov 2024

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8451

    Last Modified: 22 Jan 2026

    The reserved CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8452

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    —
    Unknown

    CVE-2020-8453

    Last Modified: 22 Jan 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. The CVE was never used.

    Published: 30 Jan 2020
    7.5
    High

    CVE-2020-3147

    Last Modified: 21 Nov 2024

    A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web interface. An attacker could exploit this vulnerability by sending a malicious request to the web interface of an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition. This vulnerability affects firmware releases prior than 1.3.7.18

    Published: 29 Jan 2020
    7.2
    High

    CVE-2020-8438

    Last Modified: 21 Nov 2024

    Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2013-3321

    Last Modified: 21 Nov 2024

    NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.

    Published: 29 Jan 2020
    6.1
    Medium

    CVE-2013-3320

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-3317

    Last Modified: 21 Nov 2024

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-3316

    Last Modified: 21 Nov 2024

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2019-10783

    Last Modified: 21 Nov 2024

    All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

    Published: 29 Jan 2020
    6.1
    Medium

    CVE-2020-3758

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2020-3719

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2020-3718

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    5.3
    Medium

    CVE-2020-3717

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a path traversal vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2020-3716

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    6.1
    Medium

    CVE-2020-3715

    Last Modified: 21 Nov 2024

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2020-3714

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2020-3713

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2020-3712

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2020-3711

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2020-3710

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2013-2574

    Last Modified: 21 Nov 2024

    An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2020-8432

    Last Modified: 21 Nov 2024

    In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-2573

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2013-2572

    Last Modified: 21 Nov 2024

    A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-2570

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2019-18634

    Last Modified: 21 Nov 2024

    In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-3215

    Last Modified: 21 Nov 2024

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2013-2569

    Last Modified: 21 Nov 2024

    A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2013-2568

    Last Modified: 21 Nov 2024

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2013-2567

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.

    Published: 29 Jan 2020
    7.5
    High

    CVE-2020-8416

    Last Modified: 21 Nov 2024

    IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.

    Published: 29 Jan 2020
    5.3
    Medium

    CVE-2020-8093

    Last Modified: 21 Nov 2024

    A vulnerability in the AntivirusforMac binary as used in Bitdefender Antivirus for Mac allows an attacker to inject a library using DYLD environment variable to cause third-party code execution

    Published: 29 Jan 2020
    1.6
    Low

    CVE-2020-8092

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender Antivirus for Mac versions prior to 8.0.0.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2020-7247

    Last Modified: 7 Nov 2025

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2019-7655

    Last Modified: 21 Nov 2024

    Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of the login form. This issue was resolved in Wowza Streaming Engine 4.8.5.

    Published: 29 Jan 2020
    7.8
    High

    CVE-2019-7656

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files. By injecting a payload into one of those files, it will run with the same privileges as the Wowza server, root. For example, /usr/local/WowzaStreamingEngine/bin/tune.sh could be replaced with a Trojan horse. This issue was resolved in Wowza Streaming Engine 4.8.5.

    Published: 29 Jan 2020
    6.5
    Medium

    CVE-2019-7654

    Last Modified: 21 Nov 2024

    Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.

    Published: 29 Jan 2020
    4.3
    Medium

    CVE-2020-2107

    Last Modified: 21 Nov 2024

    Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 29 Jan 2020
    7.6
    High

    CVE-2020-2108

    Last Modified: 21 Nov 2024

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2020-2106

    Last Modified: 21 Nov 2024

    Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations.

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2013-0161

    Last Modified: 21 Nov 2024

    Havalite CMS 1.1.7 has a stored XSS vulnerability

    Published: 29 Jan 2020
    5.4
    Medium

    CVE-2012-5776

    Last Modified: 21 Nov 2024

    Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.

    Published: 29 Jan 2020
    8.8
    High

    CVE-2012-4383

    Last Modified: 21 Nov 2024

    contao prior to 2.11.4 has a sql injection vulnerability

    Published: 29 Jan 2020
    8.8
    High

    CVE-2020-7965

    Last Modified: 21 Nov 2024

    flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2019-20217

    Last Modified: 21 Nov 2024

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2019-20216

    Last Modified: 21 Nov 2024

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

    Published: 29 Jan 2020
    9.8
    Critical

    CVE-2019-20215

    Last Modified: 21 Nov 2024

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

    Published: 29 Jan 2020