Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6191 1 Sap 1 Landscape Management 2020-02-19 9.0 HIGH 7.2 HIGH
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
CVE-2020-9025 1 Iteris 2 Vantage Velocity, Vantage Velocity Firmware 2020-02-19 4.3 MEDIUM 6.1 MEDIUM
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
CVE-2020-9026 1 Eltex-co 4 Ntp-2, Ntp-2 Firmware, Ntp-rg-1402g and 1 more 2020-02-19 10.0 HIGH 9.8 CRITICAL
ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.
CVE-2015-3309 1 Etherpad 1 Etherpad 2020-02-19 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is due to an incomplete fix to CVE-2015-3297.
CVE-2020-9027 1 Eltex-co 4 Ntp-2, Ntp-2 Firmware, Ntp-rg-1402g and 1 more 2020-02-19 10.0 HIGH 9.8 CRITICAL
ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.
CVE-2020-8843 1 Istio 1 Istio 2020-02-19 5.8 MEDIUM 7.4 HIGH
An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy selectively applies to a source equal to ingress. To exploit this vulnerability, someone has to encode a source.uid in this header. This feature is disabled by default in Istio 1.3 and 1.4.
CVE-2014-3208 1 Askpop3d Project 1 Askpop3d 2020-02-19 5.0 MEDIUM 7.5 HIGH
A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),
CVE-2012-5179 1 Boatmob 2 Boat Browser, Boat Browser Mini 2020-02-19 2.1 LOW N/A
The Boat Browser application before 4.2 and Boat Browser Mini application before 3.9 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
CVE-2013-5581 2020-02-19 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2020-8803 1 Salesagility 1 Suitecrm 2020-02-19 7.5 HIGH 9.8 CRITICAL
SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.
CVE-2020-9268 1 Soplanning 1 Soplanning 2020-02-19 5.0 MEDIUM 7.5 HIGH
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
CVE-2020-8802 1 Salesagility 1 Suitecrm 2020-02-19 7.5 HIGH 9.8 CRITICAL
SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.
CVE-2020-8800 1 Salesagility 1 Suitecrm 2020-02-19 6.5 MEDIUM 8.8 HIGH
SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.
CVE-2020-0014 1 Google 1 Android 2020-02-19 4.3 MEDIUM 5.5 MEDIUM
It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520
CVE-2013-1401 1 Cardozatechnologies 1 Wordpress Poll 2020-02-19 7.5 HIGH 9.8 CRITICAL
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.
CVE-2020-5530 1 Realestateconnected 1 Easy Property Listings 2020-02-19 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2015-2104 2020-02-19 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2019-13966 1 Combodo 1 Itop 2020-02-19 4.3 MEDIUM 6.1 MEDIUM
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar to CVE-2015-6544 (which is only about the dashboard title).
CVE-2019-13965 1 Combodo 1 Itop 2020-02-19 4.3 MEDIUM 6.1 MEDIUM
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to webservices/export.php, webservices/cron.php, or env-production/itop-backup/backup.php. By default, any XSS sent to the administrator can be transformed to remote command execution because of CVE-2018-10642 (still working through 2.6.0) The Reflective XSS can also become a stored XSS within the same account because of another vulnerability.
CVE-2013-1400 1 Cardozatechnologies 1 Wordpress Poll 2020-02-19 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
CVE-2019-4392 1 Hcltech 1 Appscan 2020-02-19 10.0 HIGH 9.8 CRITICAL
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
CVE-2013-5106 1 Python-mode Project 1 Python-mode 2020-02-19 6.8 MEDIUM 8.8 HIGH
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-4211 1 Openx 1 Openx 2020-02-19 7.5 HIGH 9.8 CRITICAL
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code
CVE-2020-7237 1 Cacti 1 Cacti 2020-02-19 9.0 HIGH 8.8 HIGH
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
CVE-2014-3860 1 Xilisoft 1 Video Converter 2020-02-19 4.4 MEDIUM 7.8 HIGH
Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability
CVE-2020-9266 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
CVE-2020-9267 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2020-9270 1 Icehrm 1 Icehrm 2020-02-19 6.8 MEDIUM 8.8 HIGH
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
CVE-2020-9271 1 Icehrm 1 Icehrm 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
CVE-2020-9029 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 6.4 MEDIUM 6.5 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
CVE-2020-9028 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 4.3 MEDIUM 6.1 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
CVE-2020-9030 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 6.4 MEDIUM 6.5 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
CVE-2020-9031 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 6.4 MEDIUM 6.5 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
CVE-2020-9032 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 6.4 MEDIUM 6.5 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
CVE-2020-9033 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2020-02-19 6.4 MEDIUM 6.5 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
CVE-2015-9253 1 Php 1 Php 2020-02-19 6.8 MEDIUM 6.5 MEDIUM
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution functions (e.g., passthru, exec, shell_exec, or system) with a non-blocking STDIN stream, causing this master process to consume 100% of the CPU, and consume disk space with a large volume of error logs, as demonstrated by an attack by a customer of a shared-hosting facility.
CVE-2020-9007 1 Codologic 1 Codoforum 2020-02-18 3.5 LOW 5.4 MEDIUM
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
CVE-2013-6022 1 Tiki 1 Tikiwiki Cms\/groupware 2020-02-18 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
CVE-2018-16455 1 Marketplace Script Project 1 Marketplace Script 2020-02-18 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword.
CVE-2020-9016 1 Dolibarr 1 Dolibarr 2020-02-18 3.5 LOW 5.4 MEDIUM
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
CVE-2020-8839 1 Chiyu-t 2 Bf-430, Bf-430 Firmware 2020-02-18 4.3 MEDIUM 6.1 MEDIUM
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cgi TF_submask field.
CVE-2019-16754 1 Riot-os 1 Riot 2020-02-18 5.0 MEDIUM 7.5 HIGH
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server response. To do so, the attacker needs to know the MQTT MsgID of a pending MQTT protocol message and the ephemeral port used by RIOT's MQTT implementation. Additionally, the server IP address is required for spoofing the packet.
CVE-2019-15702 1 Riot-os 1 Riot 2020-02-18 5.0 MEDIUM 7.5 HIGH
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an unknown zero-length option.
CVE-2015-7890 1 Samsung 2 Galaxy S6 Edge, Galaxy S6 Edge Firmware 2020-02-18 4.9 MEDIUM 5.5 MEDIUM
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
CVE-2019-10191 2 Fedoraproject, Nic 2 Fedora, Knot Resolver 2020-02-18 5.0 MEDIUM 7.5 HIGH
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.
CVE-2017-7510 1 Redhat 1 Ovirt-engine 2020-02-18 4.0 MEDIUM 8.8 HIGH
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
CVE-2018-9069 2 Hp, Lenovo 133 310s-14isk, 310s-14isk Firmware, 320-15ikbra and 130 more 2020-02-18 7.0 HIGH 5.9 MEDIUM
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
CVE-2013-3494 1 Umplayer Project 1 Umplayer 2020-02-18 9.3 HIGH 7.8 HIGH
A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code.
CVE-2020-8962 1 Dlink 2 Dir-842, Dir-842 Firmware 2020-02-18 7.5 HIGH 9.8 CRITICAL
A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when handling a POST request to the /MTFWU endpoint.
CVE-2020-9012 1 Gluu 1 Gluu Server 2020-02-18 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.