Latest CVE Feed
-
5.3
MEDIUMCVE-2020-9407
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.... Read more
Affected Products : online_weather- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9406
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.... Read more
Affected Products : online_weather- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9405
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.... Read more
Affected Products : online_weather- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2020-9404
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.... Read more
Affected Products : pactware- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9403
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.... Read more
Affected Products : pactware- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9402
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates ... Read more
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9399
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux.... Read more
- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9398
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.... Read more
Affected Products : ispconfig- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2020-9395
An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata ... Read more
Affected Products : rtl8195am_firmware rtl8711af_firmware rtl8711am_firmware rtl8710af_firmware rtl8711af rtl8711am rtl8195am rtl8710af- Published: Jul. 06, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9394
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.... Read more
Affected Products : pricing_table_by_supsystic- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2020-9393
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.... Read more
Affected Products : pricing_table_by_supsystic- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9392
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve pricing table inf... Read more
Affected Products : pricing_table_by_supsystic- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9391
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move ... Read more
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9390
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.... Read more
Affected Products : squaredup- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9389
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.... Read more
Affected Products : squaredup- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-9388
CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboa... Read more
Affected Products : squaredup- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9387
In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.... Read more
Affected Products : mahara- Published: Apr. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9386
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.... Read more
Affected Products : mahara- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9385
A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode generation.... Read more
Affected Products : zint- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9384
An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authenticated users to achieve account takeover via manipulation of POST parameters. NOTE: This vulnerability may on... Read more
Affected Products : roc_partner_settlement- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024