CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2012-1258

    Last Modified: 21 Nov 2024

    cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

    Published: 9 Jan 2020
    7.8
    High

    CVE-2016-5311

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path restrictions, which could let a local malicious user obtain system privileges.

    Published: 9 Jan 2020
    8.1
    High

    CVE-2019-6319

    Last Modified: 21 Nov 2024

    HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

    Published: 9 Jan 2020
    8.1
    High

    CVE-2019-6320

    Last Modified: 21 Nov 2024

    Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2019-6330

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

    Published: 9 Jan 2020
    3.3
    Low

    CVE-2019-6331

    Last Modified: 21 Nov 2024

    An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.

    Published: 9 Jan 2020
    4.8
    Medium

    CVE-2019-6332

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be exploited to allow cross-site scripting (XSS). Affected products and versions include: HP DeskJet 2600 All-in-One Printer series model numbers 4UJ28B, V1N01A - V1N08A, Y5H60A - Y5H80A; HP DeskJet Ink Advantage 2600 All-in-One Printer series model numbers V1N02A - V1N02B, Y5Z00A - Y5Z04B; HP DeskJet Ink Advantage 5000 All-in-One Printer series model numbers M2U86A - M2U89B; HP DeskJet Ink Advantage 5200 All-in-One Printer series model numbers M2U76A - M2U78B; HP ENVY 5000 All-in-One Printer series model numbers M2U85A - M2U85B, M2U91A - M2U94B, Z4A54A - Z4A74A; HP ENVY Photo 6200 All-in-One Printer series model numbers K7G18A-K7G26B, K7S21B, Y0K13D - Y0K15A; HP ENVY Photo 7100 All-in-One Printer series model numbers 3XD89A, K7G93A-K7G99A, Z3M37A - Z3M52A; HP ENVY Photo 7800 All-in-One Printer series model numbers K7R96A, K7S00A - K7S10D, Y0G42D - Y0G52B; HP Ink Tank Wireless 410 series model numbers Z4B53A - Z4B55A, Z6Z95A - Z6Z99A, 4DX94A - 4DX95A, 4YF79A, Z7A01A; HP OfficeJet 5200 All-in-One Printer series model numbers M2U75A, M2U81A-M2U84B, Z4B12A - Z4B14A, Z4B27A - Z4B29A; HP Smart Tank Wireless 450 series model numbers Z4B56A, Z6Z96A - Z6Z98A.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2020-6167

    Last Modified: 21 Nov 2024

    A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.

    Published: 9 Jan 2020
    5.3
    Medium

    CVE-2020-1810

    Last Modified: 21 Nov 2024

    There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2018-12380

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-17009. Reason: This candidate is a duplicate of CVE-2019-17009. Notes: All CVE users should reference CVE-2019-17009 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Jan 2020
    4.6
    Medium

    CVE-2020-1786

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow the attacker to bypass digital balance function.

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2019-4651

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.

    Published: 9 Jan 2020
    6.6
    Medium

    CVE-2020-1787

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege of guest user to access to the host user's desktop in an instant, without unlocking the screen lock of the host user.

    Published: 9 Jan 2020
    4.4
    Medium

    CVE-2020-1826

    Last Modified: 21 Nov 2024

    Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerability. Due to a module using weak encryption tool, an attacker with the root permission may exploit the vulnerability to obtain some information.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2019-14920

    Last Modified: 21 Nov 2024

    Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an authenticated attacker to gain root execution privileges over the device via a hidden etc_ro/web/adm/system_command.asp shell feature.

    Published: 9 Jan 2020
    7.8
    High

    CVE-2019-14919

    Last Modified: 21 Nov 2024

    An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.

    Published: 9 Jan 2020
    5.4
    Medium

    CVE-2019-14918

    Last Modified: 21 Nov 2024

    XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpcliinfo.asp.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-11981

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11984. Reason: This candidate is a duplicate of CVE-2019-11984. Notes: All CVE users should reference CVE-2019-11984 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Jan 2020
    8.8
    High

    CVE-2019-20224

    Last Modified: 21 Nov 2024

    netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2018-18516

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2018-18515

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2018-18514

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 9 Jan 2020
    5.5
    Medium

    CVE-2014-3753

    Last Modified: 21 Nov 2024

    AgileBits 1Password through 1.0.9.340 allows security feature bypass

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2014-3449

    Last Modified: 21 Nov 2024

    BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2014-3448

    Last Modified: 21 Nov 2024

    BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload

    Published: 9 Jan 2020
    7.5
    High

    CVE-2014-3447

    Last Modified: 21 Nov 2024

    BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability

    Published: 9 Jan 2020
    7.5
    High

    CVE-2014-3211

    Last Modified: 11 Apr 2025

    Publify before 8.0.1 is vulnerable to a Denial of Service attack

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2014-2650

    Last Modified: 21 Nov 2024

    Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

    Published: 9 Jan 2020
    9.8
    Critical

    CVE-2014-2651

    Last Modified: 21 Nov 2024

    Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

    Published: 9 Jan 2020
    7.5
    High

    CVE-2014-2686

    Last Modified: 21 Nov 2024

    Ansible prior to 1.5.4 mishandles the evaluation of some strings.

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2020-5308

    Last Modified: 21 Nov 2024

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2019-19494

    Last Modified: 21 Nov 2024

    Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-16788

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20043. Reason: This candidate is a duplicate of CVE-2019-20043. Notes: All CVE users should reference CVE-2019-20043 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Jan 2020
    6.5
    Medium

    CVE-2020-5205

    Last Modified: 21 Nov 2024

    In Pow (Hex package) before 1.0.16, the use of Plug.Session in Pow.Plug.Session is susceptible to session fixation attacks if a persistent session store is used for Plug.Session, such as Redis or a database. Cookie store, which is used in most Phoenix apps, doesn't have this vulnerability.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2019-16773

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20042. Reason: This candidate is a duplicate of CVE-2019-20042. Notes: All CVE users should reference CVE-2019-20042 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Jan 2020
    6.1
    Medium

    CVE-2020-6632

    Last Modified: 21 Nov 2024

    In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.

    Published: 9 Jan 2020
    8.8
    High

    CVE-2020-6628

    Last Modified: 21 Nov 2024

    Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.

    Published: 9 Jan 2020
    6.5
    Medium

    CVE-2020-6629

    Last Modified: 21 Nov 2024

    Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

    Published: 9 Jan 2020
    5.5
    Medium

    CVE-2020-6630

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

    Published: 9 Jan 2020
    5.5
    Medium

    CVE-2020-6631

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c.

    Published: 9 Jan 2020
    7.5
    High

    CVE-2020-25649

    Last Modified: 25 Aug 2026

    A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

    Published: 9 Jan 2020
    7.5
    High

    CVE-2019-14855

    Last Modified: 21 Nov 2024

    A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

    Published: 9 Jan 2020
    7.1
    High

    CVE-2020-6625

    Last Modified: 21 Nov 2024

    jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.

    Published: 9 Jan 2020
    5.9
    Medium

    CVE-2020-6750

    Last Modified: 21 Nov 2024

    GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.

    Published: 9 Jan 2020
    6.8
    Medium

    CVE-2019-20180

    Last Modified: 21 Nov 2024

    The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.

    Published: 9 Jan 2020
    5.3
    Medium

    CVE-2019-20372

    Last Modified: 21 Nov 2024

    NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

    Published: 9 Jan 2020
    —
    Unknown

    CVE-2020-6645

    Last Modified: 17 Mar 2025

    Not used

    Published: 9 Jan 2020
    7.1
    High

    CVE-2020-6624

    Last Modified: 21 Nov 2024

    jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.

    Published: 9 Jan 2020
    6.5
    Medium

    CVE-2019-11292

    Last Modified: 21 Nov 2024

    Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6617

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

    Published: 8 Jan 2020