CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2020-8275

    Last Modified: 21 Nov 2024

    Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

    Published: 6 Jan 2021
    5.4
    Medium

    CVE-2020-8281

    Last Modified: 21 Nov 2024

    A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.

    Published: 6 Jan 2021
    9.8
    Critical

    CVE-2020-36178

    Last Modified: 21 Nov 2024

    oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.

    Published: 6 Jan 2021
    5.3
    Medium

    CVE-2020-29041

    Last Modified: 21 Nov 2024

    A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5128

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5127

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5126

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5125

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5124

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5123

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5122

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5121

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5120

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5119

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5117

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5118

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5116

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5115

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5114

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5113

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5112

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5111

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5110

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5109

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5108

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5107

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5106

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5105

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    5.7
    Medium

    CVE-2021-21236

    Last Modified: 21 Nov 2024

    CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression denial of service (REDoS) vulnerability. When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time. This is fixed in version 2.5.1. See Referenced GitHub advisory for more information.

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5104

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    5.4
    Medium

    CVE-2019-16962

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.

    Published: 6 Jan 2021
    5.4
    Medium

    CVE-2019-16954

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    —
    Unknown

    CVE-2020-5102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none

    Published: 6 Jan 2021
    9.8
    Critical

    CVE-2020-36177

    Last Modified: 21 Nov 2024

    RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.

    Published: 6 Jan 2021
    5.3
    Medium

    CVE-2020-27283

    Last Modified: 2 Jun 2026

    An attacker could send a specially crafted message to Crimson 3.1 (Build versions prior to 3119.001) that could leak arbitrary memory locations.

    Published: 6 Jan 2021
    7.5
    High

    CVE-2020-27279

    Last Modified: 2 Jun 2026

    A NULL pointer deference vulnerability has been identified in the protocol converter. An attacker could send a specially crafted packet that could reboot the device running Crimson 3.1 (Build versions prior to 3119.001).

    Published: 6 Jan 2021
    9.1
    Critical

    CVE-2020-27285

    Last Modified: 2 Jun 2026

    The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

    Published: 6 Jan 2021
    7.8
    High

    CVE-2020-13545

    Last Modified: 21 Nov 2024

    An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.

    Published: 6 Jan 2021
    7.8
    High

    CVE-2020-13544

    Last Modified: 21 Nov 2024

    An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.

    Published: 6 Jan 2021
    7.5
    High

    CVE-2020-36176

    Last Modified: 21 Nov 2024

    The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs.

    Published: 6 Jan 2021
    9.8
    Critical

    CVE-2012-10001

    Last Modified: 21 Nov 2024

    The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

    Published: 6 Jan 2021
    5.3
    Medium

    CVE-2020-36173

    Last Modified: 21 Nov 2024

    The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

    Published: 6 Jan 2021
    5.3
    Medium

    CVE-2020-36175

    Last Modified: 21 Nov 2024

    The Ninja Forms plugin before 3.4.27.1 for WordPress allows attackers to bypass validation via the email field.

    Published: 6 Jan 2021
    6.5
    Medium

    CVE-2020-36174

    Last Modified: 21 Nov 2024

    The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.

    Published: 6 Jan 2021
    6.1
    Medium

    CVE-2020-36172

    Last Modified: 21 Nov 2024

    The Advanced Custom Fields plugin before 5.8.12 for WordPress mishandles the escaping of strings in Select2 dropdowns, potentially leading to XSS.

    Published: 6 Jan 2021
    6.1
    Medium

    CVE-2020-36171

    Last Modified: 21 Nov 2024

    The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.

    Published: 6 Jan 2021
    6.1
    Medium

    CVE-2020-8160

    Last Modified: 21 Nov 2024

    MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.

    Published: 6 Jan 2021
    5.3
    Medium

    CVE-2020-36170

    Last Modified: 21 Nov 2024

    The Ultimate Member plugin before 2.1.13 for WordPress mishandles hidden name="timestamp" fields in forms.

    Published: 6 Jan 2021
    8.8
    High

    CVE-2020-8884

    Last Modified: 21 Nov 2024

    rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to execute arbitrary code as SYSTEM because of improper deserialization over named pipes.

    Published: 6 Jan 2021