CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-27852

    Last Modified: 21 Nov 2024

    A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

    Published: 20 Jan 2021
    4.8
    Medium

    CVE-2020-27850

    Last Modified: 21 Nov 2024

    A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

    Published: 20 Jan 2021
    6.1
    Medium

    CVE-2020-13133

    Last Modified: 21 Nov 2024

    Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) unauthenticated users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1

    Published: 20 Jan 2021
    4.8
    Medium

    CVE-2020-13134

    Last Modified: 21 Nov 2024

    Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1.

    Published: 20 Jan 2021
    6.1
    Medium

    CVE-2020-25385

    Last Modified: 21 Nov 2024

    Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.

    Published: 20 Jan 2021
    8.8
    High

    CVE-2020-19364

    Last Modified: 21 Nov 2024

    OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

    Published: 20 Jan 2021
    6.5
    Medium

    CVE-2020-19363

    Last Modified: 21 Nov 2024

    Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.

    Published: 20 Jan 2021
    6.1
    Medium

    CVE-2020-19362

    Last Modified: 21 Nov 2024

    Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

    Published: 20 Jan 2021
    6.1
    Medium

    CVE-2020-19361

    Last Modified: 21 Nov 2024

    Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.

    Published: 20 Jan 2021
    7.5
    High

    CVE-2020-19360

    Last Modified: 21 Nov 2024

    Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.

    Published: 20 Jan 2021
    7.5
    High

    CVE-2021-3115

    Last Modified: 21 Nov 2024

    Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

    Published: 20 Jan 2021
    8.8
    High

    CVE-2020-35217

    Last Modified: 21 Nov 2024

    Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker does not even need to provide a CSRF token in the request because the framework does not consider it. The cookies are automatically sent by the browser and the verification will always succeed, leading to a successful CSRF attack.

    Published: 20 Jan 2021
    6.5
    Medium

    CVE-2021-20326

    Last Modified: 21 Nov 2024

    A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.

    Published: 20 Jan 2021
    6.3
    Medium

    CVE-2021-23326

    Last Modified: 21 Nov 2024

    This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/src/load-git.ts allows arbitrary command injection.

    Published: 20 Jan 2021
    6.5
    Medium

    CVE-2021-3114

    Last Modified: 21 Nov 2024

    In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.

    Published: 20 Jan 2021
    6.1
    Medium

    CVE-2020-28707

    Last Modified: 21 Nov 2024

    The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (empty) before proceeding to eval the data.method received from the postMessage. However, on a different website. JavaScript code can call window.open for the vulnerable WordPress instance and do a postMessage(msg,'*') for that object.

    Published: 19 Jan 2021
    —
    Unknown

    CVE-2020-29598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requester. Notes: none

    Published: 19 Jan 2021
    5.7
    Medium

    CVE-2020-27269

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications lacks replay protection measures, which allows unauthenticated, physically proximate attackers to replay communication sequences via Bluetooth Low Energy.

    Published: 19 Jan 2021
    6.5
    Medium

    CVE-2020-27268

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass checks for default PINs via Bluetooth Low Energy.

    Published: 19 Jan 2021
    6.5
    Medium

    CVE-2020-27266

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control vulnerability in the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows physically proximate attackers to bypass user authentication checks via Bluetooth Low Energy.

    Published: 19 Jan 2021
    4.3
    Medium

    CVE-2020-11997

    Last Modified: 21 Nov 2024

    Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able to see which other users have accessed that connection, as well as the IP addresses from which that connection was accessed, even if those users do not otherwise have permission to see other users.

    Published: 19 Jan 2021
    8.8
    High

    CVE-2020-27264

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications use deterministic keys, which allows unauthenticated, physically proximate attackers to brute-force the keys via Bluetooth Low Energy.

    Published: 19 Jan 2021
    6.5
    Medium

    CVE-2020-27258

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy.

    Published: 19 Jan 2021
    6.8
    Medium

    CVE-2020-27256

    Last Modified: 21 Nov 2024

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.

    Published: 19 Jan 2021
    7.2
    High

    CVE-2021-21263

    Last Modified: 21 Nov 2024

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that input is not validated or cast to its expected type before being passed to the query builder, an unexpected number of query bindings can be added to the query. In some situations, this will simply lead to no results being returned by the query builder; however, it is possible certain queries could be affected in a way that causes the query to return unexpected results.

    Published: 19 Jan 2021
    6.5
    Medium

    CVE-2020-8581

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.

    Published: 19 Jan 2021
    9.8
    Critical

    CVE-2020-35929

    Last Modified: 21 Nov 2024

    In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

    Published: 19 Jan 2021
    5.7
    Medium

    CVE-2020-27276

    Last Modified: 21 Nov 2024

    SOOIL Developments Co Ltd DiabecareRS,AnyDana-i & AnyDana-A, the communication protocol of the insulin pump and its AnyDana-i & AnyDana-A mobile apps doesn't use adequate measures to authenticate the communicating entities before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the authentication sequence via Bluetooth Low Energy.

    Published: 19 Jan 2021
    5.7
    Medium

    CVE-2020-27272

    Last Modified: 21 Nov 2024

    SOOIL Developments CoLtd DiabecareRS, AnyDana-i, AnyDana-A, The communication protocol of the insulin pump and AnyDana-i,AnyDana-A mobile apps doesn't use adequate measures to authenticate the pump before exchanging keys, which allows unauthenticated, physically proximate attackers to eavesdrop the keys and spoof the pump via BLE.

    Published: 19 Jan 2021
    5.7
    Medium

    CVE-2020-27270

    Last Modified: 21 Nov 2024

    SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).

    Published: 19 Jan 2021
    6.1
    Medium

    CVE-2021-3184

    Last Modified: 21 Nov 2024

    MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

    Published: 19 Jan 2021
    8.1
    High

    CVE-2021-22498

    Last Modified: 21 Nov 2024

    XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnerability affects versions 12.x, 12.60 Patch 5 and earlier, 15.0.1 Patch 2 and earlier and 15.5. The vulnerability could be exploited to allow an XML External Entity Injection.

    Published: 19 Jan 2021
    8.8
    High

    CVE-2020-27733

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

    Published: 19 Jan 2021
    9.1
    Critical

    CVE-2021-25323

    Last Modified: 21 Nov 2024

    The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

    Published: 19 Jan 2021
    6.1
    Medium

    CVE-2021-25324

    Last Modified: 21 Nov 2024

    MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

    Published: 19 Jan 2021
    6.1
    Medium

    CVE-2021-25325

    Last Modified: 21 Nov 2024

    MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.

    Published: 19 Jan 2021
    7.5
    High

    CVE-2020-4881

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the lack of server hostname verification for SSL/TLS communication. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 190851.

    Published: 19 Jan 2021
    5.3
    Medium

    CVE-2020-4873

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836.

    Published: 19 Jan 2021
    5.5
    Medium

    CVE-2020-4871

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.

    Published: 19 Jan 2021
    7.5
    High

    CVE-2021-3183

    Last Modified: 21 Nov 2024

    Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.

    Published: 19 Jan 2021
    5.9
    Medium

    CVE-2020-28482

    Last Modified: 21 Nov 2024

    This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter

    Published: 19 Jan 2021
    5.9
    Medium

    CVE-2020-28479

    Last Modified: 21 Nov 2024

    The package jointjs before 3.3.0 are vulnerable to Denial of Service (DoS) via the unsetByPath function.

    Published: 19 Jan 2021
    7.3
    High

    CVE-2020-28480

    Last Modified: 21 Nov 2024

    The package jointjs before 3.3.0 are vulnerable to Prototype Pollution via util.setByPath (https://resources.jointjs.com/docs/jointjs/v3.2/joint.htmlutil.setByPath). The path used the access the object's key and set the value is not properly sanitized, leading to a Prototype Pollution.

    Published: 19 Jan 2021
    5.3
    Medium

    CVE-2020-28481

    Last Modified: 21 Nov 2024

    The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.

    Published: 19 Jan 2021
    8
    High

    CVE-2021-3182

    Last Modified: 21 Nov 2024

    D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 19 Jan 2021
    8.8
    High

    CVE-2020-23342

    Last Modified: 21 Nov 2024

    A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

    Published: 19 Jan 2021
    9
    Critical

    CVE-2020-35128

    Last Modified: 21 Nov 2024

    Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. These actions include changing the user passwords, altering user or email addresses, or adding a new administrator to the system.

    Published: 19 Jan 2021
    9
    Critical

    CVE-2020-35129

    Last Modified: 21 Nov 2024

    Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on the target user’s behalf, including changing the user’s password or email address or changing the attacker’s user role from a low-privileged user to an administrator account.

    Published: 19 Jan 2021
    5.9
    Medium

    CVE-2020-20950

    Last Modified: 21 Nov 2024

    Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

    Published: 19 Jan 2021
    6.8
    Medium

    CVE-2020-23522

    Last Modified: 21 Nov 2024

    Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.

    Published: 19 Jan 2021