CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2020-35537

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 17 Dec 2020
    5.3
    Medium

    CVE-2020-4908

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attacks against the system.

    Published: 16 Dec 2020
    5.3
    Medium

    CVE-2020-4907

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published: 16 Dec 2020
    3.3
    Low

    CVE-2020-4906

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.

    Published: 16 Dec 2020
    5.9
    Medium

    CVE-2020-4905

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain sensitive information, caused by a man in the middle attack. By SSL striping, an attacker could exploit this vulnerability to obtain sensitive information.

    Published: 16 Dec 2020
    6.5
    Medium

    CVE-2020-4904

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.

    Published: 16 Dec 2020
    6.1
    Medium

    CVE-2020-4658

    Last Modified: 21 Nov 2024

    IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186095.

    Published: 16 Dec 2020
    6.1
    Medium

    CVE-2020-4657

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186094.

    Published: 16 Dec 2020
    8.8
    High

    CVE-2020-28931

    Last Modified: 21 Nov 2024

    Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.

    Published: 16 Dec 2020
    5.4
    Medium

    CVE-2020-28930

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2020-28929

    Last Modified: 21 Nov 2024

    Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

    Published: 16 Dec 2020
    6.4
    Medium

    CVE-2020-26274

    Last Modified: 21 Nov 2024

    In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2020-7781

    Last Modified: 21 Nov 2024

    This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-35133

    Last Modified: 21 Nov 2024

    irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

    Published: 16 Dec 2020
    5.4
    Medium

    CVE-2019-14478

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the context of the user's browser if the victim opens or searches for a node whose "Display Name" contains an XSS payload.

    Published: 16 Dec 2020
    5.4
    Medium

    CVE-2019-14481

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover.

    Published: 16 Dec 2020
    6.5
    Medium

    CVE-2019-14476

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems.

    Published: 16 Dec 2020
    8.8
    High

    CVE-2019-14479

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-7837

    Last Modified: 21 Nov 2024

    An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web page. This issue affects: Infraware ML Report 2.19.312.0000.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-5360

    Last Modified: 21 Nov 2024

    Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.

    Published: 16 Dec 2020
    5.8
    Medium

    CVE-2020-5359

    Last Modified: 21 Nov 2024

    Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.

    Published: 16 Dec 2020
    6.1
    Medium

    CVE-2020-26198

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC9 versions prior to 4.32.10.00 and 4.40.00.00 contain a reflected cross-site scripting vulnerability in the iDRAC9 web application. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link.

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2019-14482

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 16 Dec 2020
    8.8
    High

    CVE-2019-14483

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager.

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2019-14480

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.

    Published: 16 Dec 2020
    5.5
    Medium

    CVE-2019-14477

    Last Modified: 21 Nov 2024

    AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.

    Published: 16 Dec 2020
    7.2
    High

    CVE-2020-29607

    Last Modified: 16 Apr 2025

    A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.

    Published: 16 Dec 2020
    3.6
    Low

    CVE-2020-4008

    Last Modified: 21 Nov 2024

    The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited number of files with output from the sensor installation.

    Published: 16 Dec 2020
    5.3
    Medium

    CVE-2020-14248

    Last Modified: 21 Nov 2024

    BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-14254

    Last Modified: 21 Nov 2024

    TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

    Published: 16 Dec 2020
    8.8
    High

    CVE-2020-25622

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

    Published: 16 Dec 2020
    8.4
    High

    CVE-2020-25621

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.

    Published: 16 Dec 2020
    7.8
    High

    CVE-2020-25620

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.

    Published: 16 Dec 2020
    4.4
    Medium

    CVE-2020-25619

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary key pair) to access network services on the 127.0.0.1 interface, even though this feature was only intended for user-to-agent communication.

    Published: 16 Dec 2020
    8.8
    High

    CVE-2020-25618

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).

    Published: 16 Dec 2020
    8.8
    High

    CVE-2020-25617

    Last Modified: 21 Nov 2024

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-5683

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-5682

    Last Modified: 21 Nov 2024

    Improper input validation in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 16 Dec 2020
    5.2
    Medium

    CVE-2020-26273

    Last Modified: 21 Nov 2024

    osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's ATTACH verb, someone with administrative access to osquery can cause reads and writes to arbitrary sqlite databases on disk. This _does_ allow arbitrary files to be created, but they will be sqlite databases. It does not appear to allow existing non-sqlite files to be overwritten. This has been patched in osquery 4.6.0. There are several mitigating factors and possible workarounds. In some deployments, the people with access to these interfaces may be considered administrators. In some deployments, configuration is managed by a central tool. This tool can filter for the `ATTACH` keyword. osquery can be run as non-root user. Because this also limits the desired access levels, this requires deployment specific testing and configuration.

    Published: 16 Dec 2020
    7.1
    High

    CVE-2020-27781

    Last Modified: 21 Nov 2024

    User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

    Published: 16 Dec 2020
    7.5
    High

    CVE-2020-29652

    Last Modified: 21 Nov 2024

    A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

    Published: 16 Dec 2020
    5.3
    Medium

    CVE-2020-35453

    Last Modified: 21 Nov 2024

    HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2020-35476

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

    Published: 16 Dec 2020
    9.8
    Critical

    CVE-2020-35193

    Last Modified: 21 Nov 2024

    The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35469

    Last Modified: 21 Nov 2024

    The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root user. Systems deployed using affected versions of the Terracotta Server OSS container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35468

    Last Modified: 21 Nov 2024

    The Appbase streams Docker image 2.1.2 contains a blank password for the root user. Systems deployed using affected versions of the streams container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35467

    Last Modified: 21 Nov 2024

    The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35466

    Last Modified: 21 Nov 2024

    The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35464

    Last Modified: 21 Nov 2024

    Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-35463

    Last Modified: 21 Nov 2024

    Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

    Published: 15 Dec 2020