CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2020-35657

    Last Modified: 21 Nov 2024

    Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

    Published: 23 Dec 2020
    7.2
    High

    CVE-2020-35656

    Last Modified: 21 Nov 2024

    Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36189

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36186

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36185

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-35728

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).

    Published: 23 Dec 2020
    8.2
    High

    CVE-2020-36323

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked.

    Published: 23 Dec 2020
    6
    Medium

    CVE-2020-35503

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36187

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36188

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.

    Published: 23 Dec 2020
    8.1
    High

    CVE-2020-36184

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.

    Published: 23 Dec 2020
    9.8
    Critical

    CVE-2020-35665

    Last Modified: 21 Nov 2024

    An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.

    Published: 23 Dec 2020
    7.1
    High

    CVE-2020-28641

    Last Modified: 21 Nov 2024

    In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.

    Published: 22 Dec 2020
    4.7
    Medium

    CVE-2020-14874

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Cloud Infrastructure Identity and Access Management product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure Identity and Access Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Identity and Access Management accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Identity and Access Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cloud Infrastructure Identity and Access Management.

    Published: 22 Dec 2020
    9.8
    Critical

    CVE-2020-24675

    Last Modified: 21 Nov 2024

    In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.

    Published: 22 Dec 2020
    9.8
    Critical

    CVE-2020-24673

    Last Modified: 21 Nov 2024

    In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. This can lead to a loss of confidentiality and data integrity or even affect the product behavior and its availability.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-24674

    Last Modified: 21 Nov 2024

    In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.

    Published: 22 Dec 2020
    9.8
    Critical

    CVE-2020-24683

    Last Modified: 21 Nov 2024

    The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.

    Published: 22 Dec 2020
    7
    High

    CVE-2020-24680

    Last Modified: 21 Nov 2024

    In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.

    Published: 22 Dec 2020
    7.5
    High

    CVE-2020-24679

    Last Modified: 21 Nov 2024

    A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-24677

    Last Modified: 21 Nov 2024

    Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.

    Published: 22 Dec 2020
    7.8
    High

    CVE-2020-24676

    Last Modified: 21 Nov 2024

    In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-24678

    Last Modified: 21 Nov 2024

    An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.

    Published: 22 Dec 2020
    5.9
    Medium

    CVE-2020-27338

    Last Modified: 21 Nov 2024

    An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the DHCPv6 client component allows an unauthenticated remote attacker to cause an Out of Bounds Read, and possibly a Denial of Service via adjacent network access.

    Published: 22 Dec 2020
    7.3
    High

    CVE-2020-27337

    Last Modified: 30 Sept 2025

    An issue was discovered in Treck IPv6 before 6.0.1.68. Improper Input Validation in the IPv6 component allows an unauthenticated remote attacker to cause an Out of Bounds Write, and possibly a Denial of Service via network access.

    Published: 22 Dec 2020
    3.7
    Low

    CVE-2020-27336

    Last Modified: 30 Sept 2025

    An issue was discovered in Treck IPv6 before 6.0.1.68. Improper input validation in the IPv6 component when handling a packet sent by an unauthenticated remote attacker could result in an out-of-bounds read of up to three bytes via network access.

    Published: 22 Dec 2020
    10
    Critical

    CVE-2020-25066

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in the Treck HTTP Server component before 6.0.1.68 allows remote attackers to cause a denial of service (crash/reset) or to possibly execute arbitrary code.

    Published: 22 Dec 2020
    5.3
    Medium

    CVE-2020-14270

    Last Modified: 21 Nov 2024

    HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability to obtain information about the XPages software running on the Domino server.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-14231

    Last Modified: 21 Nov 2024

    A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.

    Published: 22 Dec 2020
    5.5
    Medium

    CVE-2020-35609

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability.

    Published: 22 Dec 2020
    7.8
    High

    CVE-2020-35608

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP functionality to trigger this vulnerability.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-13547

    Last Modified: 21 Nov 2024

    A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, resulting in memory corruption and arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 22 Dec 2020
    8
    High

    CVE-2020-24581

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.

    Published: 22 Dec 2020
    7.5
    High

    CVE-2020-24580

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-24579

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.

    Published: 22 Dec 2020
    6.5
    Medium

    CVE-2020-24578

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-13570

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-13560

    Last Modified: 21 Nov 2024

    A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-13557

    Last Modified: 21 Nov 2024

    A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 22 Dec 2020
    7.8
    High

    CVE-2020-25106

    Last Modified: 21 Nov 2024

    Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-29396

    Last Modified: 21 Nov 2024

    A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leading to privilege escalation.

    Published: 22 Dec 2020
    4.3
    Medium

    CVE-2019-11786

    Last Modified: 21 Nov 2024

    Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.

    Published: 22 Dec 2020
    4.3
    Medium

    CVE-2019-11785

    Last Modified: 21 Nov 2024

    Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given access to, and subscribe to receive future messages.

    Published: 22 Dec 2020
    6.5
    Medium

    CVE-2019-11784

    Last Modified: 21 Nov 2024

    Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party to.

    Published: 22 Dec 2020
    6.5
    Medium

    CVE-2019-11782

    Last Modified: 21 Nov 2024

    Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.

    Published: 22 Dec 2020
    6.5
    Medium

    CVE-2019-11783

    Last Modified: 21 Nov 2024

    Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.

    Published: 22 Dec 2020
    6.5
    Medium

    CVE-2018-15645

    Last Modified: 21 Nov 2024

    Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users to create arbitrary records via crafted payloads, which may allow privilege escalation.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2019-11781

    Last Modified: 21 Nov 2024

    Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their account via crafted links, leading to privilege escalation.

    Published: 22 Dec 2020
    5.4
    Medium

    CVE-2018-15641

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authenticated internal users to inject arbitrary web script in the browser of a victim via crafted calendar event attributes.

    Published: 22 Dec 2020
    6.1
    Medium

    CVE-2018-15634

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via a crafted link.

    Published: 22 Dec 2020