CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-4633

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 could allow a remote attacker to execute arbitrary code on the system, caused by formula injection due to improper input validation.

    Published: 11 Dec 2020
    3.5
    Low

    CVE-2020-28838

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.

    Published: 11 Dec 2020
    6.1
    Medium

    CVE-2020-17515

    Last Modified: 13 Feb 2025

    The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7792

    Last Modified: 21 Nov 2024

    This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-7790

    Last Modified: 21 Nov 2024

    This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.

    Published: 11 Dec 2020
    6.7
    Medium

    CVE-2021-3411

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 11 Dec 2020
    8.8
    High

    CVE-2020-35135

    Last Modified: 21 Nov 2024

    The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF.

    Published: 11 Dec 2020
    5.4
    Medium

    CVE-2020-35132

    Last Modified: 21 Nov 2024

    An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.

    Published: 11 Dec 2020
    4.3
    Medium

    CVE-2020-26411

    Last Modified: 21 Nov 2024

    A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.

    Published: 11 Dec 2020
    5.4
    Medium

    CVE-2020-35127

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-26408

    Last Modified: 21 Nov 2024

    A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile

    Published: 11 Dec 2020
    4.8
    Medium

    CVE-2020-35126

    Last Modified: 21 Nov 2024

    Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.

    Published: 11 Dec 2020
    4.3
    Medium

    CVE-2020-13357

    Last Modified: 21 Nov 2024

    An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in a project.

    Published: 11 Dec 2020
    3.1
    Low

    CVE-2020-26412

    Last Modified: 21 Nov 2024

    Removed group members were able to use the To-Do functionality to retrieve updated information on confidential epics starting in GitLab EE 13.2 before 13.6.2.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-26413

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-26417

    Last Modified: 21 Nov 2024

    Information disclosure via GraphQL in GitLab CE/EE 13.1 and later exposes private group and project membership. This affects versions >=13.6 to <13.6.2, >=13.5 to <13.5.5, and >=13.1 to <13.4.7.

    Published: 11 Dec 2020
    4
    Medium

    CVE-2020-26416

    Last Modified: 21 Nov 2024

    Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

    Published: 11 Dec 2020
    4.3
    Medium

    CVE-2020-26415

    Last Modified: 21 Nov 2024

    Information about the starred projects for private user profiles was exposed via the GraphQL API starting from 12.2 via the REST API. This affects GitLab >=12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.

    Published: 11 Dec 2020
    7.8
    High

    CVE-2020-13520

    Last Modified: 21 Nov 2024

    An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code execution. To trigger this vulnerability, victim needs to access an attacker-provided malformed file.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-13530

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-13556

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 11 Dec 2020
    7
    High

    CVE-2020-24440

    Last Modified: 21 Nov 2024

    Adobe Prelude version 9.0.1 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Dec 2020
    7
    High

    CVE-2020-24447

    Last Modified: 21 Nov 2024

    Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Dec 2020
    8.8
    High

    CVE-2020-9301

    Last Modified: 21 Nov 2024

    Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-25191

    Last Modified: 21 Nov 2024

    Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.

    Published: 11 Dec 2020
    6.5
    Medium

    CVE-2020-25838

    Last Modified: 21 Nov 2024

    Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive information.

    Published: 11 Dec 2020
    7.2
    High

    CVE-2020-24637

    Last Modified: 21 Nov 2024

    Two vulnerabilities in ArubaOS GRUB2 implementation allows for an attacker to bypass secureboot. Successful exploitation of this vulnerability this could lead to remote compromise of system integrity by allowing an attacker to load an untrusted or modified kernel in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-24633

    Last Modified: 21 Nov 2024

    There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-24634

    Last Modified: 21 Nov 2024

    An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

    Published: 11 Dec 2020
    4.3
    Medium

    CVE-2020-26409

    Last Modified: 21 Nov 2024

    A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

    Published: 11 Dec 2020
    8.6
    High

    CVE-2020-7560

    Last Modified: 21 Nov 2024

    A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-7549

    Last Modified: 28 May 2026

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause denial of HTTP and FTP services when a series of specially crafted requests is sent to the controller over HTTP.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7543

    Last Modified: 21 Nov 2024

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7542

    Last Modified: 21 Nov 2024

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.

    Published: 11 Dec 2020
    5.3
    Medium

    CVE-2020-7541

    Last Modified: 21 Nov 2024

    A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of sensitive data when sending a specially crafted request to the controller over HTTP.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-7540

    Last Modified: 21 Nov 2024

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7539

    Last Modified: 21 Nov 2024

    A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause a denial of service vulnerability when a specially crafted packet is sent to the controller over HTTP.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7537

    Last Modified: 21 Nov 2024

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7535

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.

    Published: 11 Dec 2020
    6.8
    Medium

    CVE-2020-28220

    Last Modified: 28 May 2026

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.

    Published: 11 Dec 2020
    7.8
    High

    CVE-2020-28219

    Last Modified: 21 Nov 2024

    A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.

    Published: 11 Dec 2020
    6.5
    Medium

    CVE-2020-28218

    Last Modified: 21 Nov 2024

    A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-28217

    Last Modified: 21 Nov 2024

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-28216

    Last Modified: 21 Nov 2024

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.

    Published: 11 Dec 2020
    9.8
    Critical

    CVE-2020-28215

    Last Modified: 21 Nov 2024

    A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.

    Published: 11 Dec 2020
    5.5
    Medium

    CVE-2020-28214

    Last Modified: 28 May 2026

    A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictable salt would provide.

    Published: 11 Dec 2020
    7.5
    High

    CVE-2020-7536

    Last Modified: 21 Nov 2024

    A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.

    Published: 11 Dec 2020
    6.4
    Medium

    CVE-2020-27837

    Last Modified: 21 Nov 2024

    A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

    Published: 11 Dec 2020
    5.6
    Medium

    CVE-2020-7789

    Last Modified: 21 Nov 2024

    This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.

    Published: 11 Dec 2020
    6.5
    Medium

    CVE-2020-27838

    Last Modified: 21 Nov 2024

    A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.

    Published: 11 Dec 2020