Latest CVE Feed
-
7.5
HIGHCVE-2020-9289
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive d... Read more
- Published: Jun. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9288
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.... Read more
Affected Products : fortiwlc- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-9287
An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading mal... Read more
Affected Products : forticlient_emergency_management_server- Published: Mar. 15, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2020-9286
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.... Read more
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9283
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-9282
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.... Read more
Affected Products : mahara- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-9281
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).... Read more
- Published: Mar. 07, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9280
In SilverStripe through 4.5, files uploaded via Forms to folders migrated from Silverstripe CMS 3.x may be put to the default "/Uploads" folder instead. This affects installations which allowed upload folder protection via the optional silverstripe/secure... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-9279
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The logged-in user can perform critical tasks and take full control of the device.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2020-9278
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9277
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9276
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stack-based buffer overflow. Unauthenticated exploitation is... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9275
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9274
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end ... Read more
- Published: Feb. 26, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9272
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-9271
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.... Read more
Affected Products : icehrm- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-9270
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.... Read more
Affected Products : icehrm- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-9269
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.... Read more
Affected Products : soplanning- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-9268
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.... Read more
Affected Products : soplanning- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024