CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-4942

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.

    Published: 4 Jan 2021
    6.7
    Medium

    CVE-2020-4928

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.

    Published: 4 Jan 2021
    3.8
    Low

    CVE-2020-4919

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 has insufficient logout controls which could allow an authenticated privileged user to impersonate another user on the system. IBM X-Force ID: 191395.

    Published: 4 Jan 2021
    4.4
    Medium

    CVE-2020-4918

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 could allow l local privileged user to disclose sensitive information due to an insecure direct object reference in sell service console for the Platform System Manager. IBM X-Force ID: 191392.

    Published: 4 Jan 2021
    8.8
    High

    CVE-2020-4917

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391.

    Published: 4 Jan 2021
    4.8
    Medium

    CVE-2020-4916

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191390.

    Published: 4 Jan 2021
    4.4
    Medium

    CVE-2020-4913

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.

    Published: 4 Jan 2021
    7.2
    High

    CVE-2020-4912

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 Self Service Console could allow a privilege escalation by capturing the user request URL when logged in as a privileged user. IBM X-Force ID: 191287.

    Published: 4 Jan 2021
    4.8
    Medium

    CVE-2020-4910

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191274.

    Published: 4 Jan 2021
    4.8
    Medium

    CVE-2020-4909

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191273.

    Published: 4 Jan 2021
    9.8
    Critical

    CVE-2020-28464

    Last Modified: 21 Nov 2024

    This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

    Published: 4 Jan 2021
    7.5
    High

    CVE-2020-7771

    Last Modified: 21 Nov 2024

    The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

    Published: 4 Jan 2021
    5.4
    Medium

    CVE-2019-16960

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

    Published: 4 Jan 2021
    5.4
    Medium

    CVE-2019-16956

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

    Published: 4 Jan 2021
    9.8
    Critical

    CVE-2021-3007

    Last Modified: 21 Nov 2024

    Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized

    Published: 4 Jan 2021
    8.8
    High

    CVE-2021-21495

    Last Modified: 21 Nov 2024

    MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.

    Published: 4 Jan 2021
    4.8
    Medium

    CVE-2021-21494

    Last Modified: 21 Nov 2024

    MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read the centralmka2 (session token) cookie, which is not set to HTTPOnly.

    Published: 4 Jan 2021
    7.5
    High

    CVE-2020-35965

    Last Modified: 21 Nov 2024

    decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations.

    Published: 4 Jan 2021
    5.3
    Medium

    CVE-2021-42778

    Last Modified: 3 Nov 2025

    A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

    Published: 4 Jan 2021
    6.8
    Medium

    CVE-2020-24386

    Last Modified: 21 Nov 2024

    An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

    Published: 4 Jan 2021
    7.5
    High

    CVE-2020-25275

    Last Modified: 21 Nov 2024

    Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

    Published: 4 Jan 2021
    8.1
    High

    CVE-2020-8265

    Last Modified: 30 Apr 2025

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.

    Published: 4 Jan 2021
    5.5
    Medium

    CVE-2021-36978

    Last Modified: 21 Nov 2024

    QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

    Published: 4 Jan 2021
    —
    Unknown

    CVE-2020-36123

    Last Modified: 2 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 4 Jan 2021
    6.5
    Medium

    CVE-2020-8287

    Last Modified: 30 Apr 2025

    Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.

    Published: 4 Jan 2021
    3.3
    Low

    CVE-2021-3588

    Last Modified: 21 Nov 2024

    The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.

    Published: 4 Jan 2021
    5.4
    Medium

    CVE-2020-35509

    Last Modified: 30 Jun 2025

    A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 4 Jan 2021
    6.5
    Medium

    CVE-2020-35964

    Last Modified: 21 Nov 2024

    track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.

    Published: 3 Jan 2021
    7.8
    High

    CVE-2020-35963

    Last Modified: 21 Nov 2024

    flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.

    Published: 3 Jan 2021
    7.5
    High

    CVE-2020-35962

    Last Modified: 21 Nov 2024

    The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.

    Published: 3 Jan 2021
    7.5
    High

    CVE-2021-3006

    Last Modified: 21 Nov 2024

    The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021.

    Published: 3 Jan 2021
    5.5
    Medium

    CVE-2020-28841

    Last Modified: 21 Nov 2024

    MyDrivers64.sys in DriverGenius 9.61.3708.3054 allows attackers to cause a system crash via the ioctl command 0x9c402000 to \\.\MyDrivers0_0_1.

    Published: 3 Jan 2021
    6.5
    Medium

    CVE-2020-35952

    Last Modified: 21 Nov 2024

    login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.

    Published: 3 Jan 2021
    4.3
    Medium

    CVE-2021-3005

    Last Modified: 21 Nov 2024

    MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified titulo (aka invoice number) value to the central/recibo.php URI.

    Published: 3 Jan 2021
    7.5
    High

    CVE-2021-3004

    Last Modified: 21 Nov 2024

    The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

    Published: 3 Jan 2021
    5.4
    Medium

    CVE-2020-35655

    Last Modified: 21 Nov 2024

    In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

    Published: 3 Jan 2021
    5.3
    Medium

    CVE-2020-7071

    Last Modified: 21 Nov 2024

    In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.

    Published: 3 Jan 2021
    7.1
    High

    CVE-2020-35653

    Last Modified: 21 Nov 2024

    In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.

    Published: 3 Jan 2021
    8.8
    High

    CVE-2020-35654

    Last Modified: 21 Nov 2024

    In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.

    Published: 3 Jan 2021
    7.5
    High

    CVE-2020-28851

    Last Modified: 21 Nov 2024

    In x/text in Go 1.15.4, an "index out of range" panic occurs in language.ParseAcceptLanguage while parsing the -u- extension. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

    Published: 2 Jan 2021
    7.5
    High

    CVE-2020-28852

    Last Modified: 21 Nov 2024

    In x/text in Go before v0.3.5, a "slice bounds out of range" panic occurs in language.ParseAcceptLanguage while processing a BCP 47 tag. (x/text/language is supposed to be able to parse an HTTP Accept-Language header.)

    Published: 2 Jan 2021
    6.1
    Medium

    CVE-2021-3002

    Last Modified: 21 Nov 2024

    Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.

    Published: 1 Jan 2021
    9
    Critical

    CVE-2020-35717

    Last Modified: 21 Nov 2024

    zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true).

    Published: 1 Jan 2021
    8.8
    High

    CVE-2020-35944

    Last Modified: 21 Nov 2024

    An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS.

    Published: 1 Jan 2021
    9.9
    Critical

    CVE-2020-35945

    Last Modified: 4 Feb 2026

    An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

    Published: 1 Jan 2021
    5.4
    Medium

    CVE-2020-35946

    Last Modified: 21 Nov 2024

    An issue was discovered in the All in One SEO Pack plugin before 3.6.2 for WordPress. The SEO Description and Title fields are vulnerable to unsanitized input from a Contributor, leading to stored XSS.

    Published: 1 Jan 2021
    7.4
    High

    CVE-2020-35947

    Last Modified: 21 Nov 2024

    An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.

    Published: 1 Jan 2021
    9.9
    Critical

    CVE-2020-35948

    Last Modified: 21 Nov 2024

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

    Published: 1 Jan 2021
    10
    Critical

    CVE-2020-35949

    Last Modified: 21 Nov 2024

    An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.

    Published: 1 Jan 2021
    9.8
    Critical

    CVE-2020-35950

    Last Modified: 21 Nov 2024

    An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint).

    Published: 1 Jan 2021