CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-35378

    Last Modified: 21 Nov 2024

    SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-14244

    Last Modified: 21 Nov 2024

    A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-29227

    Last Modified: 21 Nov 2024

    An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

    Published: 14 Dec 2020
    6.5
    Medium

    CVE-2020-17511

    Last Modified: 13 Feb 2025

    In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.

    Published: 14 Dec 2020
    5.3
    Medium

    CVE-2020-17513

    Last Modified: 13 Feb 2025

    In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.

    Published: 14 Dec 2020
    5.3
    Medium

    CVE-2020-35236

    Last Modified: 21 Nov 2024

    The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-5639

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.

    Published: 14 Dec 2020
    7.4
    High

    CVE-2020-5665

    Last Modified: 21 Nov 2024

    Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.

    Published: 14 Dec 2020
    6.8
    Medium

    CVE-2020-5637

    Last Modified: 21 Nov 2024

    Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-5635

    Last Modified: 21 Nov 2024

    Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.

    Published: 14 Dec 2020
    6.8
    Medium

    CVE-2020-5636

    Last Modified: 21 Nov 2024

    Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-35234

    Last Modified: 21 Nov 2024

    The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links. The attacker can request a reset of the Administrator password and then use a link found there.

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-35235

    Last Modified: 21 Nov 2024

    vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 14 Dec 2020
    8.8
    High

    CVE-2020-29669

    Last Modified: 21 Nov 2024

    In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in shell access. As the admin user may read the /etc/shadow file, the password hashes of each user (including root) can be dumped. The root hash can be cracked easily which results in a complete system compromise.

    Published: 14 Dec 2020
    —
    Unknown

    CVE-2020-9001

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Dec 2020
    —
    Unknown

    CVE-2020-8999

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Dec 2020
    8.1
    High

    CVE-2020-35490

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2021-3637

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-29510

    Last Modified: 21 Nov 2024

    The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-35522

    Last Modified: 21 Nov 2024

    In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-29511

    Last Modified: 21 Nov 2024

    The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

    Published: 14 Dec 2020
    —
    Unknown

    CVE-2020-35465

    Last Modified: 3 May 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-35523

    Last Modified: 21 Nov 2024

    An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-29509

    Last Modified: 21 Nov 2024

    The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.

    Published: 14 Dec 2020
    8.1
    High

    CVE-2020-35491

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-35521

    Last Modified: 21 Nov 2024

    A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-35524

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

    Published: 14 Dec 2020
    7.5
    High

    CVE-2021-33938

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

    Published: 13 Dec 2020
    6.3
    Medium

    CVE-2020-26258

    Last Modified: 23 May 2025

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.

    Published: 13 Dec 2020
    7.5
    High

    CVE-2021-33928

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

    Published: 13 Dec 2020
    7.5
    High

    CVE-2021-33929

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

    Published: 13 Dec 2020
    6.8
    Medium

    CVE-2020-26259

    Last Modified: 23 May 2025

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has sufficient rights only by manipulating the processed input stream. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist running Java 15 or higher. No user is affected, who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.

    Published: 13 Dec 2020
    3.3
    Low

    CVE-2021-3200

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service

    Published: 13 Dec 2020
    7.5
    High

    CVE-2021-33930

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.

    Published: 13 Dec 2020
    5.7
    Medium

    CVE-2020-35207

    Last Modified: 21 Nov 2024

    An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unlocking can be bypassed by forcing the authentication result to be true through runtime manipulation. In other words, an attacker could authenticate with an arbitrary PIN. NOTE: the vendor has indicated that this is not an attack of interest within the context of their threat model, which excludes jailbroken devices

    Published: 12 Dec 2020
    5.7
    Medium

    CVE-2020-35208

    Last Modified: 21 Nov 2024

    An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by forcing the authentication result to be true through runtime manipulation. In other words, an attacker could authenticate with an arbitrary password. NOTE: the vendor has indicated that this is not an attack of interest within the context of their threat model, which excludes jailbroken devices

    Published: 12 Dec 2020
    5.4
    Medium

    CVE-2020-35199

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.

    Published: 12 Dec 2020
    6.1
    Medium

    CVE-2020-35200

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.

    Published: 12 Dec 2020
    5.4
    Medium

    CVE-2020-35202

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.

    Published: 12 Dec 2020
    5.4
    Medium

    CVE-2020-35201

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.

    Published: 12 Dec 2020
    7.5
    High

    CVE-2020-29363

    Last Modified: 21 Nov 2024

    An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.

    Published: 12 Dec 2020
    7.5
    High

    CVE-2020-29361

    Last Modified: 21 Nov 2024

    An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.

    Published: 12 Dec 2020
    5.3
    Medium

    CVE-2020-29362

    Last Modified: 21 Nov 2024

    An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

    Published: 12 Dec 2020
    9.8
    Critical

    CVE-2020-29563

    Last Modified: 21 Nov 2024

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

    Published: 11 Dec 2020
    7.8
    High

    CVE-2020-29654

    Last Modified: 21 Nov 2024

    Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-35176

    Last Modified: 21 Nov 2024

    In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-25112

    Last Modified: 21 Nov 2024

    An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-25111

    Last Modified: 21 Nov 2024

    An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-25110

    Last Modified: 21 Nov 2024

    An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-25109

    Last Modified: 21 Nov 2024

    An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

    Published: 11 Dec 2020