CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2020-29159

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 3.5.1. The default signup Role (for newly created Users) can be a privileged Role, if configured by an admin. This behvaior was unintended.

    Published: 28 Dec 2020
    7.5
    High

    CVE-2020-29160

    Last Modified: 21 Nov 2024

    An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.

    Published: 28 Dec 2020
    6.5
    Medium

    CVE-2020-29245

    Last Modified: 21 Nov 2024

    dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readAtomData.

    Published: 28 Dec 2020
    6.5
    Medium

    CVE-2020-29244

    Last Modified: 21 Nov 2024

    dhowden tag before 2020-11-19 allows "panic: runtime error: slice bounds out of range" via readTextWithDescrFrame.

    Published: 28 Dec 2020
    6.5
    Medium

    CVE-2020-29243

    Last Modified: 21 Nov 2024

    dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readAPICFrame.

    Published: 28 Dec 2020
    6.5
    Medium

    CVE-2020-29242

    Last Modified: 21 Nov 2024

    dhowden tag before 2020-11-19 allows "panic: runtime error: index out of range" via readPICFrame.

    Published: 28 Dec 2020
    7.5
    High

    CVE-2020-29194

    Last Modified: 21 Nov 2024

    Panasonic Security System WV-S2231L 4.25 allows a denial of service of the admin control panel (which will require a physical reset to restore administrative control) via Randomnum=99AC8CEC6E845B28&mode=1 in a POST request to the cgi-bin/set_factory URI.

    Published: 28 Dec 2020
    6.8
    Medium

    CVE-2020-29193

    Last Modified: 21 Nov 2024

    Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).

    Published: 28 Dec 2020
    6.8
    Medium

    CVE-2020-28096

    Last Modified: 21 Nov 2024

    FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.

    Published: 28 Dec 2020
    7.5
    High

    CVE-2020-28094

    Last Modified: 21 Nov 2024

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.

    Published: 28 Dec 2020
    7.2
    High

    CVE-2020-28093

    Last Modified: 21 Nov 2024

    On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.

    Published: 28 Dec 2020
    5.7
    Medium

    CVE-2021-3409

    Last Modified: 21 Nov 2024

    The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to (including) 5.2.0 is affected by this.

    Published: 28 Dec 2020
    7.8
    High

    CVE-2020-35492

    Last Modified: 13 Feb 2025

    A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a stack buffer overflow -> out-of-bounds WRITE. The highest impact from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 28 Dec 2020
    7.4
    High

    CVE-2020-35681

    Last Modified: 21 Nov 2024

    Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases this would result in a crash but, with correct timing, responses could be sent to the wrong client, resulting in potential leakage of session identifiers and other sensitive data. Note that this affects only the legacy Channels provided class, and not Django's similar ASGIHandler, available from Django 3.0.

    Published: 28 Dec 2020
    7.5
    High

    CVE-2020-35736

    Last Modified: 21 Nov 2024

    GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

    Published: 27 Dec 2020
    5.3
    Medium

    CVE-2020-29156

    Last Modified: 21 Nov 2024

    The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

    Published: 27 Dec 2020
    6.1
    Medium

    CVE-2020-29250

    Last Modified: 21 Nov 2024

    CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.

    Published: 27 Dec 2020
    6.1
    Medium

    CVE-2020-29249

    Last Modified: 21 Nov 2024

    CXUUCMS V3 allows class="layui-input" XSS.

    Published: 27 Dec 2020
    7.2
    High

    CVE-2020-29299

    Last Modified: 21 Nov 2024

    Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.

    Published: 27 Dec 2020
    6.1
    Medium

    CVE-2020-29204

    Last Modified: 21 Nov 2024

    XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

    Published: 27 Dec 2020
    9.8
    Critical

    CVE-2020-35729

    Last Modified: 21 Nov 2024

    KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

    Published: 27 Dec 2020
    8.1
    High

    CVE-2020-7845

    Last Modified: 21 Nov 2024

    Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.

    Published: 27 Dec 2020
    7.8
    High

    CVE-2020-8290

    Last Modified: 21 Nov 2024

    Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

    Published: 27 Dec 2020
    7.8
    High

    CVE-2020-8289

    Last Modified: 21 Nov 2024

    Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.

    Published: 27 Dec 2020
    6.1
    Medium

    CVE-2020-35738

    Last Modified: 21 Nov 2024

    WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.

    Published: 27 Dec 2020
    9.8
    Critical

    CVE-2020-35245

    Last Modified: 21 Nov 2024

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35244

    Last Modified: 21 Nov 2024

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35243

    Last Modified: 21 Nov 2024

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35242

    Last Modified: 21 Nov 2024

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-29203

    Last Modified: 21 Nov 2024

    struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT.

    Published: 26 Dec 2020
    5.5
    Medium

    CVE-2020-28759

    Last Modified: 21 Nov 2024

    The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35364

    Last Modified: 21 Nov 2024

    Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35284

    Last Modified: 21 Nov 2024

    Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation occurs on the client side, and the computation details can be easily determined because the product's source code is available.

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35362

    Last Modified: 21 Nov 2024

    DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35359

    Last Modified: 21 Nov 2024

    Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35450

    Last Modified: 21 Nov 2024

    Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.

    Published: 26 Dec 2020
    6.1
    Medium

    CVE-2020-35437

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the /_core/profile/ URI.

    Published: 26 Dec 2020
    4.8
    Medium

    CVE-2020-35349

    Last Modified: 21 Nov 2024

    Savsoft Quiz 5 is affected by: Cross Site Scripting (XSS) via field_title (aka a title on the custom fields page).

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35376

    Last Modified: 21 Nov 2024

    Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.

    Published: 26 Dec 2020
    6.5
    Medium

    CVE-2020-35347

    Last Modified: 21 Nov 2024

    CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.

    Published: 26 Dec 2020
    4.8
    Medium

    CVE-2020-35346

    Last Modified: 21 Nov 2024

    CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add.

    Published: 26 Dec 2020
    7.5
    High

    CVE-2020-35388

    Last Modified: 21 Nov 2024

    rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35575

    Last Modified: 21 Nov 2024

    A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

    Published: 26 Dec 2020
    6.1
    Medium

    CVE-2020-29172

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.

    Published: 26 Dec 2020
    6.1
    Medium

    CVE-2020-27515

    Last Modified: 21 Nov 2024

    A Cross Site Scripting (XSS) vulnerability in Savsoft Quiz v5.0 allows remote attackers to inject arbitrary web script or HTML via the Skype ID field.

    Published: 26 Dec 2020
    8.8
    High

    CVE-2020-26766

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.

    Published: 26 Dec 2020
    8.8
    High

    CVE-2020-25917

    Last Modified: 21 Nov 2024

    Stratodesk NoTouch Center before 4.4.68 is affected by: Incorrect Access Control. A low privileged user on the platform, for example a user with "helpdesk" privileges, can perform privileged operations including adding a new administrator to the platform via the easyadmin/user/submitCreateTCUser.do page.

    Published: 26 Dec 2020
    9.8
    Critical

    CVE-2020-35713

    Last Modified: 21 Nov 2024

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell metacharacters to the goform/setSysAdm page.

    Published: 26 Dec 2020
    8.8
    High

    CVE-2020-35714

    Last Modified: 21 Nov 2024

    Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

    Published: 26 Dec 2020
    8.8
    High

    CVE-2020-35715

    Last Modified: 21 Nov 2024

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.

    Published: 26 Dec 2020