CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2020-28185

    Last Modified: 21 Nov 2024

    User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.

    Published: 24 Dec 2020
    9.8
    Critical

    CVE-2020-35674

    Last Modified: 21 Nov 2024

    BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted payload that can result in sensitive information being extracted from the database, eventually leading into an application takeover. This vulnerability was introduced as a result of the developer trying to roll their own sanitization implementation in order to allow the application to be used in legacy environments.

    Published: 24 Dec 2020
    8.8
    High

    CVE-2020-35675

    Last Modified: 21 Nov 2024

    BigProf Online Invoicing System before 3.0 offers a functionality that allows an administrator to move the records of members across groups. The applicable endpoint (admin/pageTransferOwnership.php) lacks CSRF protection, resulting in an attacker being able to escalate their privileges to Administrator and effectively taking over the application.

    Published: 24 Dec 2020
    6.1
    Medium

    CVE-2020-35676

    Last Modified: 21 Nov 2024

    BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can input a crafted payload that will execute upon the application's administrator browsing the registered users' list. Once the arbitrary Javascript is executed in the context of the admin, this will cause the attacker to gain administrative privileges, effectively leading into an application takeover. This affects app/membership_signup.php and app/admin/pageViewMembers.php.

    Published: 24 Dec 2020
    4.8
    Medium

    CVE-2020-35677

    Last Modified: 21 Nov 2024

    BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. The caveat here is that an attacker would need administrative privileges in order to create the payload. One might think this completely mitigates the privilege-escalation impact as there is only one high-privileged role. However, it was discovered that the endpoint responsible for creating the group lacks CSRF protection.

    Published: 24 Dec 2020
    6.1
    Medium

    CVE-2020-35669

    Last Modified: 21 Nov 2024

    An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.

    Published: 24 Dec 2020
    2.3
    Low

    CVE-2020-2505

    Last Modified: 21 Nov 2024

    If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

    Published: 24 Dec 2020
    5.8
    Medium

    CVE-2020-2504

    Last Modified: 21 Nov 2024

    If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

    Published: 24 Dec 2020
    9
    Critical

    CVE-2020-2503

    Last Modified: 21 Nov 2024

    If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

    Published: 24 Dec 2020
    6.3
    Medium

    CVE-2020-2499

    Last Modified: 21 Nov 2024

    A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

    Published: 24 Dec 2020
    7.8
    High

    CVE-2020-5681

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 24 Dec 2020
    4.8
    Medium

    CVE-2020-5684

    Last Modified: 21 Nov 2024

    iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.

    Published: 24 Dec 2020
    7.5
    High

    CVE-2020-26289

    Last Modified: 21 Nov 2024

    date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.

    Published: 24 Dec 2020
    9.8
    Critical

    CVE-2020-28188

    Last Modified: 21 Nov 2024

    Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

    Published: 24 Dec 2020
    8.8
    High

    CVE-2020-35666

    Last Modified: 21 Nov 2024

    Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-35598

    Last Modified: 21 Nov 2024

    ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623

    Published: 23 Dec 2020
    8.8
    High

    CVE-2020-35370

    Last Modified: 21 Nov 2024

    A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.

    Published: 23 Dec 2020
    6.1
    Medium

    CVE-2020-35252

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-28074

    Last Modified: 21 Nov 2024

    SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-28073

    Last Modified: 21 Nov 2024

    SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.

    Published: 23 Dec 2020
    4.8
    Medium

    CVE-2020-28071

    Last Modified: 21 Nov 2024

    SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-28070

    Last Modified: 21 Nov 2024

    SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.

    Published: 23 Dec 2020
    8.8
    High

    CVE-2020-27397

    Last Modified: 21 Nov 2024

    Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.

    Published: 23 Dec 2020
    6.1
    Medium

    CVE-2020-13969

    Last Modified: 21 Nov 2024

    CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-13968

    Last Modified: 21 Nov 2024

    CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2018-1000893

    Last Modified: 21 Nov 2024

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2018-1000892

    Last Modified: 21 Nov 2024

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2018-1000891

    Last Modified: 21 Nov 2024

    Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.

    Published: 23 Dec 2020
    5.5
    Medium

    CVE-2020-4642

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow local attacker to cause a denial of service inside the "DB2 Management Service".

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-11719

    Last Modified: 21 Nov 2024

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-11720

    Last Modified: 21 Nov 2024

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this password.

    Published: 23 Dec 2020
    7.4
    High

    CVE-2020-11718

    Last Modified: 21 Nov 2024

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.

    Published: 23 Dec 2020
    6.1
    Medium

    CVE-2020-9439

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the search_key GET Parameter in TinCan_Content_List_Table.php, message GET Parameter in licensing.php, tc_filter_group parameter in reporting-admin-menu.php, tc_filter_user parameter in reporting-admin-menu.php, tc_filter_course parameter in reporting-admin-menu.php, tc_filter_lesson parameter in reporting-admin-menu.php, tc_filter_module parameter in reporting-admin-menu.php, tc_filter_action parameter in reporting-admin-menu.php, tc_filter_data_range parameter in reporting-admin-menu.php, or tc_filter_data_range_last parameter in reporting-admin-menu.php.

    Published: 23 Dec 2020
    9.1
    Critical

    CVE-2020-29551

    Last Modified: 21 Nov 2024

    An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php, _internal/pc/vpro.php, _internal/pc/wake.php, _internal/error_u201409.txt, _internal/runcmd.php, _internal/getConfiguration.php, ews/autoload.php, ews/del.php, ews/mod.php, ews/sync.php, utils/backup/backup_server.php, utils/backup/restore_server.php, MyScreens/timeline.config, kreator.html5/test.php, and addedlogs.txt.

    Published: 23 Dec 2020
    6.1
    Medium

    CVE-2020-35650

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the ulgm_user_last POST Parameter in user-registration-form.php, the ulgm_user_email POST Parameter in user-registration-form.php, the ulgm_code_registration POST Parameter in user-registration-form.php, the ulgm_terms_conditions POST Parameter in user-registration-form.php, the _ulgm_total_seats POST Parameter in frontend-uo_groups_buy_courses.php, the uncanny_group_signup_user_first POST Parameter in group-registration-form.php, the uncanny_group_signup_user_last POST Parameter in group-registration-form.php, the uncanny_group_signup_user_login POST Parameter in group-registration-form.php, the uncanny_group_signup_user_email POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uo_groups.php, the bulk-errors GET Parameter in frontend-uo_groups.php, or the message GET Parameter in frontend-uo_groups.php.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-35587

    Last Modified: 21 Nov 2024

    In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack technique

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-29552

    Last Modified: 21 Nov 2024

    An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.

    Published: 23 Dec 2020
    6.1
    Medium

    CVE-2020-6159

    Last Modified: 21 Nov 2024

    URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Opera for Android versions below 61.0.3076.56532.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-29550

    Last Modified: 21 Nov 2024

    An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The following files contain the password in cleartext: Profiles/urve/files/sql_db.backup, Server/data/pg_wal/000000010000000A000000DD, Server/data/base/16384/18617, and Server/data/base/17202/8708746. This causes the password to be displayed as cleartext in the HTML code as roomsreservationimport_password in /urve/roomsreservationimport/roomsreservationimport/update-HTML5.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-35586

    Last Modified: 21 Nov 2024

    In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using brute-force attacks via the /Config/service/initModel?password= Solstice Open Control API because there is no complexity requirement (e.g., it might be all digits or all lowercase letters).

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-35585

    Last Modified: 21 Nov 2024

    In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force attacks via the /lookin/info Solstice Open Control API because there are only 1.7 million possibilities.

    Published: 23 Dec 2020
    5.9
    Medium

    CVE-2020-35584

    Last Modified: 21 Nov 2024

    In Solstice Pod before 3.0.3, the web services allow users to connect to them over unencrypted channels via the Browser Look-in feature. An attacker suitably positioned to view a legitimate user's network traffic could record and monitor their interactions with the web services and obtain any information the user supplies, including Administrator passwords and screen keys.

    Published: 23 Dec 2020
    7.2
    High

    CVE-2020-35136

    Last Modified: 21 Nov 2024

    Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-25196

    Last Modified: 21 Nov 2024

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-25153

    Last Modified: 21 Nov 2024

    The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.

    Published: 23 Dec 2020
    5.3
    Medium

    CVE-2020-25192

    Last Modified: 21 Nov 2024

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.

    Published: 23 Dec 2020
    8.8
    High

    CVE-2020-25198

    Last Modified: 21 Nov 2024

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.

    Published: 23 Dec 2020
    8.8
    High

    CVE-2020-25194

    Last Modified: 21 Nov 2024

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.

    Published: 23 Dec 2020
    7.5
    High

    CVE-2020-25190

    Last Modified: 21 Nov 2024

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

    Published: 23 Dec 2020
    5.3
    Medium

    CVE-2020-35658

    Last Modified: 21 Nov 2024

    SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.

    Published: 23 Dec 2020