CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-35701

    Last Modified: 21 Nov 2024

    An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27281

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    8.8
    High

    CVE-2020-23960

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass of the user's comments, (2) restoring a deleted user, (3) installing or running modules, (4) resetting the analytics, (5) pinging the mailmotor api, (6) uploading things to the media library, (7) exporting locale.

    Published: 11 Jan 2021
    5.3
    Medium

    CVE-2019-3405

    Last Modified: 21 Nov 2024

    In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, which will cause other wireless terminals connected to disconnect from the wireless, so as to attack the router wireless by DoS. At present, the vulnerability has been effectively handled, and users can fix the vulnerability after updating the firmware version.

    Published: 11 Jan 2021
    5.3
    Medium

    CVE-2021-23253

    Last Modified: 21 Nov 2024

    Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With the URL being left-aligned, the user will only see the front part (e.g. www.safe.opera.com…) The exact amount depends on the phone screen size but the attacker can craft a number of different domains and target different phones. Starting with version 53.1 Opera Mini displays long URLs with the top-level domain label aligned to the right of the address field which mitigates the issue.

    Published: 11 Jan 2021
    7.5
    High

    CVE-2018-11246

    Last Modified: 21 Nov 2024

    K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory Leak.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-11010

    Last Modified: 21 Nov 2024

    A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2018-11005

    Last Modified: 21 Nov 2024

    A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2018-11007

    Last Modified: 21 Nov 2024

    A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-11009

    Last Modified: 21 Nov 2024

    A Buffer Overflow issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2018-11008

    Last Modified: 21 Nov 2024

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2018-11006

    Last Modified: 21 Nov 2024

    An Incorrect Access Control issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-8044

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-8726

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-8725

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-8724

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-9333

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: K7TSMngr.exe.

    Published: 11 Jan 2021
    7
    High

    CVE-2020-17534

    Last Modified: 21 Nov 2024

    There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local privilege escalation version 1.7.1 creates the temporary directory atomically without dealing with the temporary file: https://github.com/apache/netbeans-html4j/commit/fa70e507e5555e1adb4f6518479fc408a7abd0e6

    Published: 11 Jan 2021
    7.8
    High

    CVE-2018-9332

    Last Modified: 21 Nov 2024

    K7Computing Pvt Ltd K7AntiVirus Premium 15.01.00.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local).

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27293

    Last Modified: 21 Nov 2024

    Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27289

    Last Modified: 21 Nov 2024

    Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27291

    Last Modified: 21 Nov 2024

    Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27287

    Last Modified: 21 Nov 2024

    Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    3.3
    Low

    CVE-2020-24003

    Last Modified: 21 Nov 2024

    Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27275

    Last Modified: 21 Nov 2024

    Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-27277

    Last Modified: 21 Nov 2024

    Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

    Published: 11 Jan 2021
    8.8
    High

    CVE-2020-26118

    Last Modified: 21 Nov 2024

    In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be submitted to the server via an authenticated attacker to execute commands on the underlying system.

    Published: 11 Jan 2021
    7.8
    High

    CVE-2020-35483

    Last Modified: 21 Nov 2024

    AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.

    Published: 11 Jan 2021
    7.2
    High

    CVE-2020-2508

    Last Modified: 21 Nov 2024

    A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later)

    Published: 11 Jan 2021
    8.8
    High

    CVE-2020-23630

    Last Modified: 21 Nov 2024

    A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-23849

    Last Modified: 21 Nov 2024

    Stored XSS was discovered in the tree mode of jsoneditor before 9.0.2 through injecting and executing JavaScript.

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-23644

    Last Modified: 21 Nov 2024

    XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-23643

    Last Modified: 21 Nov 2024

    XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.

    Published: 11 Jan 2021
    5.5
    Medium

    CVE-2020-26800

    Last Modified: 21 Nov 2024

    A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json file may result in a denial of service.

    Published: 11 Jan 2021
    7.5
    High

    CVE-2020-17508

    Last Modified: 21 Nov 2024

    The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

    Published: 11 Jan 2021
    7.5
    High

    CVE-2020-17509

    Last Modified: 21 Nov 2024

    ATS negative cache option is vulnerable to a cache poisoning attack. If you have this option enabled, please upgrade or disable this feature. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.

    Published: 11 Jan 2021
    6.5
    Medium

    CVE-2020-13922

    Last Modified: 13 Feb 2025

    Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.

    Published: 11 Jan 2021
    9.8
    Critical

    CVE-2020-11995

    Last Modified: 13 Feb 2025

    A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserialization protool, during Hessian2 deserializing the HashMap object, some functions in the classes stored in HasMap will be executed after a series of program calls, however, those special functions may cause remote command execution. For example, the hashCode() function of the EqualsBean class in rome-1.7.0.jar will cause the remotely load malicious classes and execute malicious code by constructing a malicious request. This issue was fixed in Apache Dubbo 2.6.9 and 2.7.8.

    Published: 11 Jan 2021
    9.8
    Critical

    CVE-2021-3118

    Last Modified: 21 Nov 2024

    EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    7.5
    High

    CVE-2021-3116

    Last Modified: 21 Nov 2024

    before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data because of a boolean confusion (and versus or).

    Published: 11 Jan 2021
    5.4
    Medium

    CVE-2020-35727

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-35726

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-35725

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    5.4
    Medium

    CVE-2020-35724

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the Error.jsp file via the err parameter (or indirectly via the cpr, tcp, or abs parameter). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    5.4
    Medium

    CVE-2020-35723

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    6.5
    Medium

    CVE-2020-35722

    Last Modified: 21 Nov 2024

    CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    5.4
    Medium

    CVE-2020-35721

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseAssets.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    5.4
    Medium

    CVE-2020-35720

    Last Modified: 21 Nov 2024

    Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon name) when creating or modifying a user via the submitUser.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-35719

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Search/index.jsp file via the added parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021
    6.1
    Medium

    CVE-2020-35204

    Last Modified: 21 Nov 2024

    Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the PolicyAuthority/Common/FolderControl.jsp file via the unqID parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 11 Jan 2021