CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2018-15638

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) issue in mail module in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted channel names.

    Published: 22 Dec 2020
    6.1
    Medium

    CVE-2018-15633

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim via crafted attachment filenames.

    Published: 22 Dec 2020
    9.1
    Critical

    CVE-2018-15632

    Last Modified: 21 Nov 2024

    Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty database on which they can connect with default credentials.

    Published: 22 Dec 2020
    5.6
    Medium

    CVE-2020-28448

    Last Modified: 21 Nov 2024

    This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.

    Published: 22 Dec 2020
    5.6
    Medium

    CVE-2020-28460

    Last Modified: 21 Nov 2024

    This affects the package multi-ini before 2.1.2. It is possible to pollute an object's prototype by specifying the constructor.proto object as part of an array. This is a bypass of CVE-2020-28448.

    Published: 22 Dec 2020
    9.8
    Critical

    CVE-2020-29583

    Last Modified: 7 Nov 2025

    Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

    Published: 22 Dec 2020
    8.8
    High

    CVE-2020-29004

    Last Modified: 21 Nov 2024

    The API in the Push extension for MediaWiki through 1.35 did not require an edit token in ApiPushBase.php and therefore facilitated a CSRF attack.

    Published: 22 Dec 2020
    7.5
    High

    CVE-2020-29005

    Last Modified: 21 Nov 2024

    The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.

    Published: 22 Dec 2020
    4.3
    Medium

    CVE-2021-30152

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.

    Published: 22 Dec 2020
    6.7
    Medium

    CVE-2020-35506

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service or potential code execution with the privileges of the QEMU process.

    Published: 22 Dec 2020
    7.7
    High

    CVE-2020-26284

    Last Modified: 21 Nov 2024

    Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%PATH%` on Windows. In Hugo before version 0.79.1, if a malicious file with the same name (`exe` or `bat`) is found in the current working directory at the time of running `hugo`, the malicious command will be invoked instead of the system one. Windows users who run `hugo` inside untrusted Hugo sites are affected. Users should upgrade to Hugo v0.79.1. Other than avoiding untrusted Hugo sites, there is no workaround.

    Published: 21 Dec 2020
    6.1
    Medium

    CVE-2020-35622

    Last Modified: 21 Nov 2024

    An issue was discovered in the GlobalUsage extension for MediaWiki through 1.35.1. SpecialGlobalUsage.php calls WikiMap::makeForeignLink unsafely. The $page variable within the formatItem function was not being properly escaped, allowing for XSS under certain conditions.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-35623

    Last Modified: 21 Nov 2024

    An issue was discovered in the CasAuth extension for MediaWiki through 1.35.1. Due to improper username validation, it allowed user impersonation with trivial manipulations of certain characters within a given username. An ordinary user may be able to login as a "bureaucrat user" who has a similar username, as demonstrated by usernames that differ only in (1) bidirectional override symbols or (2) blank space.

    Published: 21 Dec 2020
    5.3
    Medium

    CVE-2020-35624

    Last Modified: 21 Nov 2024

    An issue was discovered in the SecurePoll extension for MediaWiki through 1.35.1. The non-admin vote list contains a full vote timestamp, which may provide unintended clues about how a voting process unfolded.

    Published: 21 Dec 2020
    8.8
    High

    CVE-2020-35625

    Last Modified: 21 Nov 2024

    An issue was discovered in the Widgets extension for MediaWiki through 1.35.1. Any user with the ability to edit pages within the Widgets namespace could call any static function within any class (defined within PHP or MediaWiki) via a crafted HTML comment, related to a Smarty template. For example, a person in the Widget Editors group could use \MediaWiki\Shell\Shell::command within a comment.

    Published: 21 Dec 2020
    8.8
    High

    CVE-2020-35626

    Last Modified: 21 Nov 2024

    An issue was discovered in the PushToWatch extension for MediaWiki through 1.35.1. The primary form did not implement an anti-CSRF token and therefore was completely vulnerable to CSRF attacks against onSkinAddFooterLinks in PushToWatch.php.

    Published: 21 Dec 2020
    6.8
    Medium

    CVE-2020-26281

    Last Modified: 21 Nov 2024

    async-h1 is an asynchronous HTTP/1.1 parser for Rust (crates.io). There is a request smuggling vulnerability in async-h1 before version 2.3.0. This vulnerability affects any webserver that uses async-h1 behind a reverse proxy, including all such Tide applications. If the server does not read the body of a request which is longer than some buffer length, async-h1 will attempt to read a subsequent request from the body content starting at that offset into the body. One way to exploit this vulnerability would be for an adversary to craft a request such that the body contains a request that would not be noticed by a reverse proxy, allowing it to forge forwarded/x-forwarded headers. If an application trusted the authenticity of these headers, it could be misled by the smuggled request. Another potential concern with this vulnerability is that if a reverse proxy is sending multiple http clients' requests along the same keep-alive connection, it would be possible for the smuggled request to specify a long content and capture another user's request in its body. This content could be captured in a post request to an endpoint that allows the content to be subsequently retrieved by the adversary. This has been addressed in async-h1 2.3.0 and previous versions have been yanked.

    Published: 21 Dec 2020
    —
    Unknown

    CVE-2021-21158

    Last Modified: 17 Jan 2025

    Further investigation determines issue is not within scope of this CNA

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-29596

    Last Modified: 21 Nov 2024

    MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request.

    Published: 21 Dec 2020
    6.1
    Medium

    CVE-2020-26277

    Last Modified: 21 Nov 2024

    DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario, an attacker could induce dbdeployer to write into a system file, thus altering the computer defenses. For the attack to succeed, the following factors need to contribute: 1) The user is logged in as root. While dbdeployer is usable as root, it was designed to run as unprivileged user. 2) The user has taken a tarball from a non secure source, without testing the checksum. When the tarball is retrieved through dbdeployer, the checksum is compared before attempting to unpack. This has been fixed in version 1.58.2.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-8995

    Last Modified: 21 Nov 2024

    Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-11717

    Last Modified: 21 Nov 2024

    An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2018-7580

    Last Modified: 21 Nov 2024

    Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.

    Published: 21 Dec 2020
    8.8
    High

    CVE-2020-35151

    Last Modified: 21 Nov 2024

    The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

    Published: 21 Dec 2020
    8.8
    High

    CVE-2020-35606

    Last Modified: 21 Nov 2024

    Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-35605

    Last Modified: 24 Apr 2025

    The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-35604

    Last Modified: 21 Nov 2024

    An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-21378

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-21377

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.

    Published: 21 Dec 2020
    4.3
    Medium

    CVE-2020-4843

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.6 stores potentially sensitive information in config files that could be read by an authenticated user. IBM X-Force ID: 190048.

    Published: 21 Dec 2020
    4.9
    Medium

    CVE-2020-4842

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190046.

    Published: 21 Dec 2020
    5.9
    Medium

    CVE-2020-4841

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 190045.

    Published: 21 Dec 2020
    6.1
    Medium

    CVE-2020-4840

    Last Modified: 21 Nov 2024

    IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 190044.

    Published: 21 Dec 2020
    6.1
    Medium

    CVE-2020-26275

    Last Modified: 21 Nov 2024

    The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect the browser to a different malicious website. All jupyter servers running without a base_url prefix are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may *appear* safe, but ultimately redirect to a spoofed server on the public internet. This same vulnerability was patched in upstream notebook v5.7.8. This is fixed in jupyter_server 1.1.1. If upgrade is not available, a workaround can be to run your server on a url prefix: "jupyter server --ServerApp.base_url=/jupyter/".

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-4870

    Last Modified: 21 Nov 2024

    IBM MQ 9.2 CD and LTS are vulnerable to a denial of service attack caused by an error processing connecting applications. IBM X-Force ID: 190833.

    Published: 21 Dec 2020
    5.4
    Medium

    CVE-2020-4794

    Last Modified: 21 Nov 2024

    IBM Automation Workstream Services 19.0.3, 20.0.1, 20.0.2, IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.6 could allow an authenticated user to obtain sensitive information or cuase a denial of service due to iimproper authorization checking. IBM X-Force ID: 189445.

    Published: 21 Dec 2020
    6.4
    Medium

    CVE-2020-4757

    Last Modified: 21 Nov 2024

    IBM FileNet Content Manager and IBM Content Navigator 3.0.CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188600.

    Published: 21 Dec 2020
    5.4
    Medium

    CVE-2020-4555

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-4988

    Last Modified: 21 Nov 2024

    Loopback 8.0.0 contains a vulnerability that could allow an attacker to manipulate or pollute Javascript values and cause a denial of service or possibly execute code. IBM X-Force ID: 192706.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-5808

    Last Modified: 21 Nov 2024

    In certain scenarios in Tenable.sc prior to 5.17.0, a scanner could potentially be used outside the user's defined scan zone without a particular zone being specified within the Automatic Distribution configuration.

    Published: 21 Dec 2020
    6.6
    Medium

    CVE-2020-25860

    Last Modified: 21 Nov 2024

    The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-6882

    Last Modified: 21 Nov 2024

    ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices by sending specific topics. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-6881

    Last Modified: 21 Nov 2024

    ZTE E8810/E8820/E8822 series routers have an MQTT DoS vulnerability, which is caused by the failure of the device to verify the validity of abnormal messages. A remote attacker could connect to the MQTT server and send an MQTT exception message to the specified device, which will cause the device to deny service. This affects:<ZXHN E8810, ZXHN E8820, ZXHN E8822><E8810 V1.0.26, E8810 V2.0.1, E8820 V1.1.3L, E8820 V2.0.13, E8822 V2.0.13>

    Published: 21 Dec 2020
    6.5
    Medium

    CVE-2020-14225

    Last Modified: 21 Nov 2024

    HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-27254

    Last Modified: 21 Nov 2024

    Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.

    Published: 21 Dec 2020
    7.5
    High

    CVE-2020-26263

    Last Modified: 21 Nov 2024

    tlslite-ng is an open source python library that implements SSL and TLS cryptographic protocols. In tlslite-ng before versions 0.7.6 and 0.8.0-alpha39, the code that performs decryption and padding check in RSA PKCS#1 v1.5 decryption is data dependant. In particular, the code has multiple ways in which it leaks information about the decrypted ciphertext. It aborts as soon as the plaintext doesn't start with 0x00, 0x02. All TLS servers that enable RSA key exchange as well as applications that use the RSA decryption API directly are vulnerable. This is patched in versions 0.7.6 and 0.8.0-alpha39. Note: the patches depend on Python processing the individual bytes in side-channel free manner, this is known to not the case (see reference). As such, users that require side-channel resistance are recommended to use different TLS implementations, as stated in the security policy of tlslite-ng.

    Published: 21 Dec 2020
    7.7
    High

    CVE-2020-17526

    Last Modified: 13 Feb 2025

    Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect users who have changed the default value for `[webserver] secret_key` config.

    Published: 21 Dec 2020
    6.5
    Medium

    CVE-2020-3999

    Last Modified: 8 Aug 2025

    VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx process leading to a denial of service condition.

    Published: 21 Dec 2020
    6.5
    Medium

    CVE-2019-16959

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

    Published: 21 Dec 2020
    9.8
    Critical

    CVE-2020-35276

    Last Modified: 21 Nov 2024

    EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.

    Published: 21 Dec 2020