CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-17502

    Last Modified: 21 Nov 2024

    Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

    Published: 8 Jan 2021
    9.8
    Critical

    CVE-2020-8584

    Last Modified: 21 Nov 2024

    Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.

    Published: 8 Jan 2021
    5.3
    Medium

    CVE-2020-27260

    Last Modified: 21 Nov 2024

    Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7 v2.x messages via multiple expected parameters.

    Published: 8 Jan 2021
    5.4
    Medium

    CVE-2020-27262

    Last Modified: 21 Nov 2024

    Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability exists in the affected products that allow an attacker to inject arbitrary web script or HTML via the filename parameter to multiple update endpoints of the administrative web interface.

    Published: 8 Jan 2021
    8.8
    High

    CVE-2020-5805

    Last Modified: 21 Nov 2024

    In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credentials to login to QCC.

    Published: 8 Jan 2021
    8.1
    High

    CVE-2020-5804

    Last Modified: 21 Nov 2024

    Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path prior to using it in file deletion operations. An authenticated, remote attacker can leverage this vulnerability to delete arbitrary remote files as SYSTEM or root.

    Published: 8 Jan 2021
    5.5
    Medium

    CVE-2021-1066

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to unexpected consumption of resources, which in turn may lead to denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1065

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1064

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.8
    High

    CVE-2021-1063

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    6.3
    Medium

    CVE-2021-1061

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1062

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1060

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1058

    Last Modified: 21 Nov 2024

    NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.8
    High

    CVE-2021-1059

    Last Modified: 21 Nov 2024

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input index is not validated, which may lead to integer overflow, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    7.8
    High

    CVE-2021-1057

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

    Published: 8 Jan 2021
    4.3
    Medium

    CVE-2020-4667

    Last Modified: 21 Nov 2024

    IBM Engineering Requirements Quality Assistant On-Premises could allow an authenticated user to obtain sensitive information due to improper input validation. IBM X-Force ID: 186282.

    Published: 8 Jan 2021
    5.4
    Medium

    CVE-2020-4666

    Last Modified: 21 Nov 2024

    IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186281.

    Published: 8 Jan 2021
    5.4
    Medium

    CVE-2020-4664

    Last Modified: 21 Nov 2024

    IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186235.

    Published: 8 Jan 2021
    5.4
    Medium

    CVE-2020-4663

    Last Modified: 21 Nov 2024

    IBM Engineering Requirements Quality Assistant On-Premises is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186234.

    Published: 8 Jan 2021
    4.4
    Medium

    CVE-2020-4606

    Last Modified: 21 Nov 2024

    IBM Security Verify Privilege Manager 10.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A local attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 184883.

    Published: 8 Jan 2021
    4.8
    Medium

    CVE-2021-3111

    Last Modified: 21 Nov 2024

    The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.

    Published: 8 Jan 2021
    9.8
    Critical

    CVE-2020-7784

    Last Modified: 21 Nov 2024

    This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:

    Published: 8 Jan 2021
    9.8
    Critical

    CVE-2020-7794

    Last Modified: 21 Nov 2024

    This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).

    Published: 8 Jan 2021
    8.1
    High

    CVE-2020-28468

    Last Modified: 21 Nov 2024

    This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.

    Published: 8 Jan 2021
    4.3
    Medium

    CVE-2020-25950

    Last Modified: 21 Nov 2024

    Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page.

    Published: 8 Jan 2021
    7.5
    High

    CVE-2020-24577

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the application's response body for a /tmp/var/passwd or /tmp/home/wan_stat URI.

    Published: 8 Jan 2021
    8.8
    High

    CVE-2021-3025

    Last Modified: 21 Nov 2024

    Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).

    Published: 8 Jan 2021
    5.3
    Medium

    CVE-2021-1055

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which improper access control may lead to denial of service and information disclosure.

    Published: 8 Jan 2021
    5.5
    Medium

    CVE-2021-1054

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.

    Published: 8 Jan 2021
    8.4
    High

    CVE-2021-1051

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.

    Published: 8 Jan 2021
    9.8
    Critical

    CVE-2020-35131

    Last Modified: 21 Nov 2024

    Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

    Published: 8 Jan 2021
    7.8
    High

    CVE-2021-1052

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.

    Published: 8 Jan 2021
    5.5
    Medium

    CVE-2021-1053

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which improper validation of a user pointer may lead to denial of service.

    Published: 8 Jan 2021
    7.1
    High

    CVE-2021-1056

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.

    Published: 8 Jan 2021
    7.5
    High

    CVE-2020-13449

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2020-13450

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS, a change to program behavior, or code execution.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2020-13451

    Last Modified: 21 Nov 2024

    An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2020-13452

    Last Modified: 21 Nov 2024

    In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2020-17500

    Last Modified: 21 Nov 2024

    Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2019-18642

    Last Modified: 21 Nov 2024

    Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential user IDs allows any user to change account details of any other user. This vulnerability could be used to change the email address of another account, even the administrator account. Upon changing another account's email address, performing a password reset to the new email address could allow an attacker to take over any account.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2019-18643

    Last Modified: 21 Nov 2024

    Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain remote code execution on the application. The application typically runs as LocalSystem as mandated in the installation guide. Patched in versions 8.10 and 9.4.

    Published: 7 Jan 2021
    8.8
    High

    CVE-2020-35745

    Last Modified: 21 Nov 2024

    PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

    Published: 7 Jan 2021
    5.3
    Medium

    CVE-2021-23241

    Last Modified: 21 Nov 2024

    MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.

    Published: 7 Jan 2021
    5.3
    Medium

    CVE-2021-23242

    Last Modified: 21 Nov 2024

    MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.

    Published: 7 Jan 2021
    5.3
    Medium

    CVE-2018-18689

    Last Modified: 27 Nov 2024

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

    Published: 7 Jan 2021
    7.5
    High

    CVE-2020-4898

    Last Modified: 21 Nov 2024

    IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190989.

    Published: 7 Jan 2021
    5.3
    Medium

    CVE-2020-4897

    Last Modified: 21 Nov 2024

    IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190988.

    Published: 7 Jan 2021
    6.5
    Medium

    CVE-2020-4896

    Last Modified: 21 Nov 2024

    IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 190987.

    Published: 7 Jan 2021
    5.4
    Medium

    CVE-2020-4895

    Last Modified: 21 Nov 2024

    IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.

    Published: 7 Jan 2021