CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2020-26178

    Last Modified: 21 Nov 2024

    In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

    Published: 18 Dec 2020
    5.4
    Medium

    CVE-2019-16955

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.

    Published: 18 Dec 2020
    5.4
    Medium

    CVE-2019-16957

    Last Modified: 21 Nov 2024

    SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.

    Published: 18 Dec 2020
    5.5
    Medium

    CVE-2020-35548

    Last Modified: 21 Nov 2024

    An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).

    Published: 18 Dec 2020
    5.5
    Medium

    CVE-2020-35549

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Any application may establish itself as the default dialer, without user interaction. The Samsung ID is SVE-2020-19172 (December 2020).

    Published: 18 Dec 2020
    9.8
    Critical

    CVE-2020-35550

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).

    Published: 18 Dec 2020
    9.8
    Critical

    CVE-2020-35551

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB write operation can be replayed, a related issue to CVE-2020-13799. The Samsung ID is SVE-2020-18100 (December 2020).

    Published: 18 Dec 2020
    5.3
    Medium

    CVE-2020-35552

    Last Modified: 21 Nov 2024

    An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chipsets) software. Attackers can obtain sensitive location information because the configuration file is incorrect. The Samsung ID is SVE-2020-18678 (December 2020).

    Published: 18 Dec 2020
    7.5
    High

    CVE-2020-35553

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Qualcomm SM8250 chipsets) software. They allows attackers to cause a denial of service (unlock failure) by triggering a power-shortage incident that causes a false-positive attack detection. The Samsung ID is SVE-2020-19678 (December 2020).

    Published: 18 Dec 2020
    7.8
    High

    CVE-2020-35554

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. There is a WebView SSL error-handler vulnerability. The LG ID is LVE-SMP-200026 (December 2020).

    Published: 18 Dec 2020
    7.8
    High

    CVE-2020-35555

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 10 software. When a dual-screen configuration is supported, the device does not lock upon disconnection of a call with the cover closed. The LG ID is LVE-SMP-200027 (December 2020).

    Published: 18 Dec 2020
    8.1
    High

    CVE-2020-27640

    Last Modified: 21 Nov 2024

    The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

    Published: 18 Dec 2020
    8.1
    High

    CVE-2020-27639

    Last Modified: 21 Nov 2024

    The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

    Published: 18 Dec 2020
    8.8
    High

    CVE-2020-27154

    Last Modified: 21 Nov 2024

    The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to view the user information and application data.

    Published: 18 Dec 2020
    7.2
    High

    CVE-2020-25608

    Last Modified: 21 Nov 2024

    The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.

    Published: 18 Dec 2020
    5.4
    Medium

    CVE-2020-25609

    Last Modified: 21 Nov 2024

    The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-27340

    Last Modified: 21 Nov 2024

    The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-25606

    Last Modified: 21 Nov 2024

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-25611

    Last Modified: 21 Nov 2024

    The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.

    Published: 18 Dec 2020
    5.3
    Medium

    CVE-2020-25610

    Last Modified: 21 Nov 2024

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.

    Published: 18 Dec 2020
    4.9
    Medium

    CVE-2020-25612

    Last Modified: 21 Nov 2024

    The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.

    Published: 18 Dec 2020
    3.3
    Low

    CVE-2020-24693

    Last Modified: 21 Nov 2024

    The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.

    Published: 18 Dec 2020
    8.8
    High

    CVE-2020-7838

    Last Modified: 21 Nov 2024

    A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72.

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-35678

    Last Modified: 21 Nov 2024

    Autobahn|Python before 20.12.3 allows redirect header injection.

    Published: 18 Dec 2020
    9.8
    Critical

    CVE-2020-11974

    Last Modified: 21 Nov 2024

    In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.

    Published: 18 Dec 2020
    3.7
    Low

    CVE-2020-26422

    Last Modified: 21 Nov 2024

    Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-35474

    Last Modified: 21 Nov 2024

    In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.

    Published: 18 Dec 2020
    5.3
    Medium

    CVE-2020-35480

    Last Modified: 21 Nov 2024

    An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths.

    Published: 18 Dec 2020
    8.1
    High

    CVE-2020-28052

    Last Modified: 12 May 2025

    An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

    Published: 18 Dec 2020
    7.5
    High

    CVE-2020-35475

    Last Modified: 21 Nov 2024

    In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is escaped correctly.)

    Published: 18 Dec 2020
    5.3
    Medium

    CVE-2020-35477

    Last Modified: 21 Nov 2024

    MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysubmit (instead of the desired behavior in which a revision-deletion form appears).

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-35478

    Last Modified: 21 Nov 2024

    MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later.

    Published: 18 Dec 2020
    6.1
    Medium

    CVE-2020-35479

    Last Modified: 21 Nov 2024

    MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.

    Published: 18 Dec 2020
    6.5
    Medium

    CVE-2020-35497

    Last Modified: 21 Nov 2024

    A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key.

    Published: 18 Dec 2020
    8.8
    High

    CVE-2020-14232

    Last Modified: 21 Nov 2024

    A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-13516

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406144 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 17 Dec 2020
    5.5
    Medium

    CVE-2020-13517

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c406104 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-13518

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver IRP 0x9c402084 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-13511

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) using the IRP 0x9c4060d4 gives a low privilege user direct access to the IN instruction that is completely unrestrained at an elevated privilege level. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-13510

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) using the IRP 0x9c4060d0 gives a low privilege user direct access to the IN instruction that is completely unrestrained at an elevated privilege level. An attacker can send a malicious IRP to trigger this vulnerability.

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-13509

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the WinRing0x64 Driver Privileged I/O Read IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) Using the IRP 0x9c4060cc gives a low privilege user direct access to the IN instruction that is completely unrestrained at an elevated privilege level. An attacker can send a malicious IRP to trigger this vulnerability and this access could allow for information leakage of sensitive data.

    Published: 17 Dec 2020
    9.8
    Critical

    CVE-2020-13931

    Last Modified: 21 Nov 2024

    If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - 7.0.8, 1.0.0 - 1.7.5 is configured to use the embedded ActiveMQ broker, and the broker config is misconfigured, a JMX port is opened on TCP port 1099, which does not include authentication. CVE-2020-11969 previously addressed the creation of the JMX management interface, however the incomplete fix did not cover this edge case.

    Published: 17 Dec 2020
    5.3
    Medium

    CVE-2020-13528

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.

    Published: 17 Dec 2020
    4.5
    Medium

    CVE-2020-13527

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 17 Dec 2020
    5.4
    Medium

    CVE-2020-12523

    Last Modified: 21 Nov 2024

    On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional independent from their configuration setting: Missing Initialization of Resource

    Published: 17 Dec 2020
    6.5
    Medium

    CVE-2020-12521

    Last Modified: 21 Nov 2024

    On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.

    Published: 17 Dec 2020
    8.8
    High

    CVE-2020-12519

    Last Modified: 21 Nov 2024

    On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.

    Published: 17 Dec 2020
    5.5
    Medium

    CVE-2020-12518

    Last Modified: 21 Nov 2024

    On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.

    Published: 17 Dec 2020
    8.8
    High

    CVE-2020-12517

    Last Modified: 21 Nov 2024

    On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).

    Published: 17 Dec 2020
    10
    Critical

    CVE-2020-12522

    Last Modified: 21 Nov 2024

    The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.

    Published: 17 Dec 2020