CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-0444

    Last Modified: 21 Nov 2024

    In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150693166References: Upstream kernel

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-0464

    Last Modified: 21 Nov 2024

    In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-0466

    Last Modified: 21 Nov 2024

    In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147802478References: Upstream kernel

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-0099

    Last Modified: 21 Nov 2024

    In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141745510

    Published: 14 Dec 2020
    7.7
    High

    CVE-2020-25234

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The LOGO! program files generated and used by the affected components offer the possibility to save user-defined functions (UDF) in a password protected way. This protection is implemented in the software that displays the information. An attacker could reverse engineer the UDFs directly from stored program files.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-25232

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an insecure random number generation function and a deprecated cryptographic function, an attacker could extract the key that is used when communicating with an affected device on port 8080/tcp.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-25235

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An attacker with access to the network traffic could derive valid logins.

    Published: 14 Dec 2020
    7.3
    High

    CVE-2020-28396

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-8022 (All versions < V16). A web server misconfiguration of the affected device can cause insecure ciphers usage by a user´s browser. An attacker in a privileged position could decrypt the communication and compromise confidentiality and integrity of the transmitted information.

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-25233

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communication with the device.

    Published: 14 Dec 2020
    6.1
    Medium

    CVE-2019-19288

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-15796

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-25228

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2019-19289

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-25229

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker could change the password or change the configuration on any affected device if using prepared messages that were generated for another device.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-25230

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Due to the usage of an outdated cipher mode on port 10005/tcp, an attacker could extract the encryption key from a captured communication with the device.

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-25231

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use this key to extract confidential information from protected program files.

    Published: 14 Dec 2020
    6.5
    Medium

    CVE-2019-19287

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse through the file system of the server based by sending specially crafted packets over the network without authentication.

    Published: 14 Dec 2020
    5.3
    Medium

    CVE-2019-19283

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive information about the server's architecture. This could allow an attacker to adapt further attacks to the version in place.

    Published: 14 Dec 2020
    5.4
    Medium

    CVE-2019-19284

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS) attacks if an attacker is able to modify content of particular web pages, causing the application to behave in unexpected ways for legitimate users.

    Published: 14 Dec 2020
    5.4
    Medium

    CVE-2019-19285

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lead to XSS attacks if unsuspecting users are tricked into accessing a malicious link.

    Published: 14 Dec 2020
    7.2
    High

    CVE-2019-19286

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if an attacker is able to modify content of particular web pages.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-20189

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.

    Published: 14 Dec 2020
    7.1
    High

    CVE-2020-14368

    Last Modified: 21 Nov 2024

    A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request Forgery (CSRF) and consequently allowing a cross-site WebSocket hijack on Theia IDE. This flaw allows an attacker to gain full access to the victim's workspace through the /services endpoint. To perform a successful attack, the attacker conducts a Man-in-the-middle attack (MITM) and tricks the victim into executing a request via an untrusted link, which performs the CSRF and the Socket hijack. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-20184

    Last Modified: 21 Nov 2024

    GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.

    Published: 14 Dec 2020
    6.1
    Medium

    CVE-2020-29304

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

    Published: 14 Dec 2020
    6.1
    Medium

    CVE-2020-29303

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote attackers to inject arbitrary web script or HTML via a POST to /wp-admin/admin.php?page=drts/directories&q=%2F with _drts_form_build_id parameter containing the XSS payload and _t_ parameter set to an invalid or non-existent CSRF token.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-20183

    Last Modified: 21 Nov 2024

    Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privileges and access certain admin pages.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-8258

    Last Modified: 21 Nov 2024

    Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-8257

    Last Modified: 21 Nov 2024

    Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-8282

    Last Modified: 21 Nov 2024

    A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-8283

    Last Modified: 21 Nov 2024

    An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

    Published: 14 Dec 2020
    5.3
    Medium

    CVE-2020-28861

    Last Modified: 21 Nov 2024

    OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-16103

    Last Modified: 21 Nov 2024

    Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); version 8.00 and prior versions.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-28860

    Last Modified: 21 Nov 2024

    OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

    Published: 14 Dec 2020
    7.1
    High

    CVE-2020-16102

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1299(MR2); 8.20 versions prior to 8.20.1218(MR4); 8.10 versions prior to 8.10.1253(MR6); 8.00 versions prior to 8.00.1252(MR7); version 7.90 and prior versions.

    Published: 14 Dec 2020
    8.2
    High

    CVE-2020-16104

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data from this database. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); 8.00 versions prior to 8.00.1228(MR6); version 7.90 and prior versions.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-27252

    Last Modified: 22 May 2025

    Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-25187

    Last Modified: 22 May 2025

    Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software stack. The heap overflow could allow an attacker to remotely execute code on the MCL Smart Patient Reader, potentially leading to control of the device

    Published: 14 Dec 2020
    8
    High

    CVE-2020-25183

    Last Modified: 22 May 2025

    Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable to bypass. This vulnerability enables an attacker to use another mobile device or malicious application on the patient’s smartphone to authenticate to the patient’s Medtronic Smart Reader, fooling the device into believing it is communicating with the original Medtronic smart phone application when executed within range of Bluetooth communication.

    Published: 14 Dec 2020
    6.1
    Medium

    CVE-2020-28859

    Last Modified: 21 Nov 2024

    OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-28858

    Last Modified: 21 Nov 2024

    OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

    Published: 14 Dec 2020
    6.1
    Medium

    CVE-2020-28857

    Last Modified: 21 Nov 2024

    OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-20136

    Last Modified: 21 Nov 2024

    QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-28856

    Last Modified: 21 Nov 2024

    OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

    Published: 14 Dec 2020
    6.5
    Medium

    CVE-2020-15733

    Last Modified: 21 Nov 2024

    An Origin Validation Error vulnerability in the SafePay component of Bitdefender Antivirus Plus allows a web resource to misrepresent itself in the URL bar. This issue affects: Bitdefender Antivirus Plus versions prior to 25.0.7.29.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-35338

    Last Modified: 21 Nov 2024

    The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-25175

    Last Modified: 21 Nov 2024

    GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-25179

    Last Modified: 21 Nov 2024

    GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

    Published: 14 Dec 2020
    7.2
    High

    CVE-2020-35382

    Last Modified: 21 Nov 2024

    SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-14268

    Last Modified: 21 Nov 2024

    A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.

    Published: 14 Dec 2020