CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2020-4893

    Last Modified: 21 Nov 2024

    IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.

    Published: 7 Jan 2021
    5.4
    Medium

    CVE-2020-4892

    Last Modified: 21 Nov 2024

    IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190979.

    Published: 7 Jan 2021
    5.3
    Medium

    CVE-2018-18688

    Last Modified: 21 Nov 2024

    The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

    Published: 7 Jan 2021
    7.5
    High

    CVE-2020-13573

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

    Published: 7 Jan 2021
    5.8
    Medium

    CVE-2020-6656

    Last Modified: 21 Nov 2024

    Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user upload a malformed .E70 file in the application. The vulnerability arises due to improper validation of user data supplied through E70 file which is causing Type Confusion.

    Published: 7 Jan 2021
    5.8
    Medium

    CVE-2020-6655

    Last Modified: 21 Nov 2024

    The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make the application crash by tricking user to upload the malformed .E70 file in the application. The vulnerability arises due to improper validation and parsing of the E70 file content by the application.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20316

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20315

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20314

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCheckLicence race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20313

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyPreviewAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20312

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read, a different issue than CVE-2018-20310 because of a different opcode.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20311

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyCPDFAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20310

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyDoAction race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    8.1
    High

    CVE-2018-20309

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.5, and PhantomPDF before 8.3.10 and 9.x before 9.5, has a proxyGetAppEdition race condition that can cause a stack-based buffer overflow or an out-of-bounds read.

    Published: 7 Jan 2021
    7.8
    High

    CVE-2018-19418

    Last Modified: 21 Nov 2024

    Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-25476

    Last Modified: 21 Nov 2024

    Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own profile, and the malicious payload will be injected and reflected in the calendar of the user who submitted the payload. An attacker could escalate its privileges in case an admin visits the calendar that injected the payload.

    Published: 7 Jan 2021
    4.2
    Medium

    CVE-2021-3011

    Last Modified: 21 Nov 2024

    An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECDSA private key after extensive physical access (and consequently produce a clone). This was demonstrated on the Google Titan Security Key, based on an NXP A7005a chip. Other FIDO U2F security keys are also impacted (Yubico YubiKey Neo and Feitian K9, K13, K21, and K40) as well as several NXP JavaCard smartcards (J3A081, J2A081, J3A041, J3D145_M59, J2D145_M59, J3D120_M60, J3D082_M60, J2D120_M60, J2D082_M60, J3D081_M59, J2D081_M59, J3D081_M61, J2D081_M61, J3D081_M59_DF, J3D081_M61_DF, J3E081_M64, J3E081_M66, J2E081_M64, J3E041_M66, J3E016_M66, J3E016_M64, J3E041_M64, J3E145_M64, J3E120_M65, J3E082_M65, J2E145_M64, J2E120_M65, J2E082_M65, J3E081_M64_DF, J3E081_M66_DF, J3E041_M66_DF, J3E016_M66_DF, J3E041_M64_DF, and J3E016_M64_DF).

    Published: 7 Jan 2021
    7.2
    High

    CVE-2020-28672

    Last Modified: 21 Nov 2024

    MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution. At monofiles/category.php:27, user input can be saved to category/[foldername]/index.php causing RCE.

    Published: 7 Jan 2021
    8.8
    High

    CVE-2020-26773

    Last Modified: 21 Nov 2024

    Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2021-3029

    Last Modified: 21 Nov 2024

    EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 7 Jan 2021
    9.8
    Critical

    CVE-2020-26972

    Last Modified: 21 Nov 2024

    The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    6.5
    Medium

    CVE-2020-26975

    Last Modified: 19 Aug 2026

    When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    6.5
    Medium

    CVE-2020-26976

    Last Modified: 21 Nov 2024

    When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    6.5
    Medium

    CVE-2020-26977

    Last Modified: 19 Aug 2026

    By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-26979

    Last Modified: 21 Nov 2024

    When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    8.8
    High

    CVE-2020-35114

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-24903

    Last Modified: 21 Nov 2024

    Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 7 Jan 2021
    4.7
    Medium

    CVE-2020-24902

    Last Modified: 21 Nov 2024

    Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-24901

    Last Modified: 3 Apr 2025

    The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-24900

    Last Modified: 21 Nov 2024

    The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

    Published: 7 Jan 2021
    6.1
    Medium

    CVE-2020-26768

    Last Modified: 21 Nov 2024

    Formstone <=1.4.16 is vulnerable to a Reflected Cross-Site Scripting (XSS) vulnerability caused by improper validation of user supplied input in the upload-target.php and upload-chunked.php files. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site once the URL is clicked or visited. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials, force malware execution, user redirection and others.

    Published: 7 Jan 2021
    6.3
    Medium

    CVE-2021-20197

    Last Modified: 3 Dec 2025

    There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

    Published: 7 Jan 2021
    7.5
    High

    CVE-2021-40330

    Last Modified: 21 Nov 2024

    git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol requests, as demonstrated by the git://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3092

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3093

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3094

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3096

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3097

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3098

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3099

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3104

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3105

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    —
    Unknown

    CVE-2021-3091

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 7 Jan 2021
    9.9
    Critical

    CVE-2020-26085

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

    Published: 6 Jan 2021
    4.8
    Medium

    CVE-2020-25498

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in URL Filter.

    Published: 6 Jan 2021
    6.1
    Medium

    CVE-2020-35262

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Digisol DG-HR3400 can be exploited via the NTP server name in Time and date module and "Keyword" in URL Filter.

    Published: 6 Jan 2021
    5.4
    Medium

    CVE-2020-8280

    Last Modified: 21 Nov 2024

    A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.

    Published: 6 Jan 2021
    6.5
    Medium

    CVE-2020-8274

    Last Modified: 21 Nov 2024

    Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

    Published: 6 Jan 2021