Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
LibRaw before 0.20-Beta3 has an out-of-bounds write in parse_exif() in metadata\exif_gps.cpp via an unrecognized AtomName and a zero value of tiff_nifds.
Published Jun 28, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Published Jun 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI)(CI)(M)) to the contents of the directory and its sub-folders. In addition, the program installs a service called IDriveService that runs as LocalSystem. Thus, any standard user can escalate privileges to NT AUTHORITY\SYSTEM by substituting the service's binary with a malicious one.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
Published Jun 28, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Argent RecoveryManager before 0xdc350d09f71c48c5D22fBE2741e4d6A03970E192, the executeRecovery function does not require any signatures in the zero-guardian case, which allows attackers to cause a denial of service (locking) or a takeover.
Published Jun 25, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
Published Jun 26, 2020 · Updated Aug 4, 2024
Medium · CVSS 6.9
In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions prior to 2.10.0 persisted the cache even after the user logged out. This is fixed in version 2.10.3. A workaround is to manually clear application data (browser's local storage) after logging into Saleor Storefront.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Published Jun 4, 2021 · Updated Aug 4, 2024
High · CVSS 7.7
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are affected by this vulnerability if all of the following conditions apply: - You are using express-jwt - You do not have **algorithms** configured in your express-jwt configuration. - You are using libraries such as jwks-rsa as the **secret**. You can fix this by specifying **algorithms** in the express-jwt configuration. See linked GHSA for example. This is also fixed in version 6.0.0.
Published Jun 30, 2020 · Updated Aug 4, 2024
High · CVSS 7.4
In Presto before version 337, authenticated users can bypass authorization checks by directly accessing internal APIs. This impacts Presto server installations with secure internal communication configured. This does not affect installations that have not configured secure internal communication, as these installations are inherently insecure. This only affects Presto server installations. This does NOT affect clients such as the CLI or JDBC driver. This vulnerability has been fixed in version 337. Additionally, this issue can be mitigated by blocking network access to internal APIs on the coordinator and workers.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MSA/SMTP.cpp in Trojita before 0.8 ignores certificate-verification errors, which allows man-in-the-middle attackers to spoof SMTP servers.
Published Jun 25, 2020 · Updated Aug 4, 2024
Critical · CVSS 9.9
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The FileExplorer component in GleamTech FileUltimate 6.1.5.0 allows XSS via an SVG document.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
playSMS through 1.4.3 is vulnerable to session fixation.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
Published Jun 29, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Published Jun 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.
Published Jun 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.
Published Jun 22, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute code on an already compromised machine.
Published Jun 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NeDi 1.9C is vulnerable to reflected cross-site scripting. The Devices-Config.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the sta GET parameter.
Published Jun 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as valid). An attacker can abuse this behavior in an application by creating multiple valid signatures where only one signature should exist. Also, an attacker might prepend these bytes with the goal of triggering memory corruption issues.
Published Jun 22, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
Published Jun 22, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.
Published Jun 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
Published Jun 22, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
Published Jun 22, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.
Published Jun 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them. This occurs in settings.php. To exploit this, an attacker would request a backup of limited files via teleporter.php. These are placed into a .tar.gz archive. The attacker then modifies the host parameter in dnsmasq.d files, and then compresses and uploads these files again.
Published Jun 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
Published Jun 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.
Published Jun 23, 2020 · Updated Aug 4, 2024