CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-5841

    Last Modified: 21 Nov 2024

    An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

    Published: 7 Jan 2020
    4.9
    Medium

    CVE-2019-6529

    Last Modified: 21 Nov 2024

    An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166).

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2020-5842

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2018-10465

    Last Modified: 21 Nov 2024

    Jamf Pro 10.x before 10.3.0 has Incorrect Access Control. Jamf Pro user accounts and groups with access to log in to Jamf Pro had full access to endpoints in the Universal API (UAPI), regardless of account privileges or privilege sets. An authenticated Jamf Pro account without required privileges could be used to perform CRUD actions (GET, POST, PUT, DELETE) on UAPI endpoints, which could result in unauthorized information disclosure, compromised data integrity, and data loss. For a full listing of available UAPI endpoints and associated CRUD actions you can navigate to /uapi/doc in your instance of Jamf Pro.

    Published: 7 Jan 2020
    9.8
    Critical

    CVE-2020-5307

    Last Modified: 21 Nov 2024

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.

    Published: 7 Jan 2020
    8.7
    High

    CVE-2019-18386

    Last Modified: 21 Nov 2024

    Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecified impact when receiving specifically crafted message payloads over a systems management communication channel

    Published: 7 Jan 2020
    9.8
    Critical

    CVE-2019-10776

    Last Modified: 21 Nov 2024

    In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2019-16154

    Last Modified: 21 Nov 2024

    An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

    Published: 7 Jan 2020
    6.5
    Medium

    CVE-2019-6700

    Last Modified: 21 Nov 2024

    An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker to retrieve the external authentication password via the HTML source code.

    Published: 7 Jan 2020
    5.5
    Medium

    CVE-2019-9465

    Last Modified: 21 Nov 2024

    In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root cause. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID: A-133258003

    Published: 7 Jan 2020
    9.8
    Critical

    CVE-2014-8673

    Last Modified: 21 Nov 2024

    Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2013-5658

    Last Modified: 21 Nov 2024

    AultWare pwStore 2010.8.30.0 has XSS

    Published: 7 Jan 2020
    7.5
    High

    CVE-2013-5657

    Last Modified: 21 Nov 2024

    AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request

    Published: 7 Jan 2020
    7.8
    High

    CVE-2013-5656

    Last Modified: 21 Nov 2024

    FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability

    Published: 7 Jan 2020
    5.4
    Medium

    CVE-2013-5638

    Last Modified: 21 Nov 2024

    Transcend WiFiSD 1.8 has persistent XSS

    Published: 7 Jan 2020
    5.4
    Medium

    CVE-2013-5637

    Last Modified: 21 Nov 2024

    PQI AirCard has persistent XSS

    Published: 7 Jan 2020
    5.4
    Medium

    CVE-2019-14879

    Last Modified: 21 Nov 2024

    A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2020-5393

    Last Modified: 21 Nov 2024

    In Appspace On-Prem through 7.1.3, an adversary can steal a session token via XSS.

    Published: 7 Jan 2020
    9.8
    Critical

    CVE-2013-5122

    Last Modified: 21 Nov 2024

    Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access

    Published: 7 Jan 2020
    5.9
    Medium

    CVE-2013-5571

    Last Modified: 21 Nov 2024

    HMailServer 5.3.x and prior: Memory Corruption which could cause DOS

    Published: 7 Jan 2020
    4.8
    Medium

    CVE-2020-5843

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2019-17015

    Last Modified: 21 Nov 2024

    During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2019-17017

    Last Modified: 21 Nov 2024

    Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    5.3
    Medium

    CVE-2019-17021

    Last Modified: 21 Nov 2024

    During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2019-17022

    Last Modified: 21 Nov 2024

    When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would result in an XSS vulnerability. Two WYSIWYG editors were identified with this behavior, more may exist. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2019-17024

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2020-6377

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2019-17016

    Last Modified: 21 Nov 2024

    When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.

    Published: 7 Jan 2020
    7.5
    High

    CVE-2019-5188

    Last Modified: 30 May 2025

    A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

    Published: 7 Jan 2020
    6.5
    Medium

    CVE-2020-1701

    Last Modified: 21 Nov 2024

    A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access to create VMs could attach any secret within their namespace, allowing them to read the contents of that secret.

    Published: 7 Jan 2020
    5.6
    Medium

    CVE-2020-7039

    Last Modified: 21 Nov 2024

    tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.

    Published: 7 Jan 2020
    7.5
    High

    CVE-2018-7794

    Last Modified: 29 May 2026

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.

    Published: 6 Jan 2020
    7.5
    High

    CVE-2019-6857

    Last Modified: 29 May 2026

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service of the controller when reading specific memory blocks using Modbus TCP.

    Published: 6 Jan 2020
    7.5
    High

    CVE-2019-6856

    Last Modified: 29 May 2026

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when writing specific physical memory blocks using Modbus TCP.

    Published: 6 Jan 2020
    7.3
    High

    CVE-2019-6855

    Last Modified: 21 Nov 2024

    Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.

    Published: 6 Jan 2020
    7.8
    High

    CVE-2019-6854

    Last Modified: 21 Nov 2024

    A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.

    Published: 6 Jan 2020
    5.4
    Medium

    CVE-2014-8674

    Last Modified: 21 Nov 2024

    Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.

    Published: 6 Jan 2020
    5.4
    Medium

    CVE-2014-9405

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary code.

    Published: 6 Jan 2020
    8.8
    High

    CVE-2015-4553

    Last Modified: 21 Nov 2024

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

    Published: 6 Jan 2020
    9.9
    Critical

    CVE-2015-5951

    Last Modified: 21 Nov 2024

    A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.

    Published: 6 Jan 2020
    6.8
    Medium

    CVE-2019-20348

    Last Modified: 21 Nov 2024

    OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to interrupt the boot sequence in order to execute arbitrary commands with root privileges and conduct further attacks.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2019-18842

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H Low Power WiFi Module with web version 1.2.2 allows attackers to leak credentials of the Wi-Fi access point the module is logged into, and the web interface login credentials, by opening a Wi-Fi access point nearby with a malicious SSID.

    Published: 6 Jan 2020
    8.8
    High

    CVE-2020-5846

    Last Modified: 21 Nov 2024

    An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full system access as the configured user (e.g., Administrator) when starting from any authenticated session (e.g., a trial account). This is fixed in the 83/830122/cbs-*-hotfix-task26000 builds.

    Published: 6 Jan 2020
    7.5
    High

    CVE-2019-18625

    Last Modified: 21 Nov 2024

    An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP Timestamp option. The client will ignore the RST ACK and the FIN ACK packets because of the bad TCP Timestamp option. Both linux and windows client are ignoring the injected packets.

    Published: 6 Jan 2020
    5.3
    Medium

    CVE-2019-16271

    Last Modified: 21 Nov 2024

    DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2019-16272

    Last Modified: 21 Nov 2024

    On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.

    Published: 6 Jan 2020
    9.8
    Critical

    CVE-2019-16273

    Last Modified: 21 Nov 2024

    DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.

    Published: 6 Jan 2020
    7.5
    High

    CVE-2019-16274

    Last Modified: 21 Nov 2024

    DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.

    Published: 6 Jan 2020
    6.6
    Medium

    CVE-2019-16716

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.2 has Incorrect Access Control.

    Published: 6 Jan 2020
    6.1
    Medium

    CVE-2014-3743

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.

    Published: 6 Jan 2020