CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-16962

    Last Modified: 28 Aug 2025

    Windows Backup Engine Elevation of Privilege Vulnerability

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-16960

    Last Modified: 28 Aug 2025

    Windows Backup Engine Elevation of Privilege Vulnerability

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-16959

    Last Modified: 28 Aug 2025

    Windows Backup Engine Elevation of Privilege Vulnerability

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-16958

    Last Modified: 28 Aug 2025

    Windows Backup Engine Elevation of Privilege Vulnerability

    Published: 9 Dec 2020
    6.3
    Medium

    CVE-2020-7339

    Last Modified: 21 Nov 2024

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network to potentially intercept communication between the Server and Sensors.

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-10143

    Last Modified: 21 Nov 2024

    Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges.

    Published: 9 Dec 2020
    5.4
    Medium

    CVE-2020-29259

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-29258

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-29257

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-16600

    Last Modified: 21 Nov 2024

    A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16599

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16593

    Last Modified: 21 Nov 2024

    A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16592

    Last Modified: 21 Nov 2024

    A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16591

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-16590

    Last Modified: 21 Nov 2024

    A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.

    Published: 9 Dec 2020
    8.8
    High

    CVE-2020-25499

    Last Modified: 21 Nov 2024

    TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-26257

    Last Modified: 21 Nov 2024

    Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. This can lead to a denial of service in which future events will not be correctly sent to other servers over federation. This affects any server which accepts federation requests from untrusted servers. The Matrix Synapse reference implementation before version 1.23.1 the implementation is vulnerable to this injection attack. Issue is fixed in version 1.23.1. As a workaround homeserver administrators could limit access to the federation API to trusted servers (for example via `federation_domain_whitelist`).

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-28086

    Last Modified: 21 Nov 2024

    pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other members' machines, and also controls one of the services already in the password store, they can rename one of the password files in the Git repository to something else: pass doesn't correctly verify that the content of a file matches the filename, so a user might be tricked into decrypting the wrong password and sending that to a service that the attacker controls. NOTE: for environments in which this threat model is of concern, signing commits can be a solution.

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-2049

    Last Modified: 21 Nov 2024

    A local privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Agent on the Windows platform that allows an authenticated local Windows user to execute programs with SYSTEM privileges. This requires the user to have the privilege to create files in the Windows root directory. This issue impacts: All versions of Cortex XDR Agent 7.1 with content update 149 and earlier versions; All versions of Cortex XDR Agent 7.2 with content update 149 and earlier versions.

    Published: 9 Dec 2020
    5.5
    Medium

    CVE-2020-2020

    Last Modified: 21 Nov 2024

    An improper handling of exceptional conditions vulnerability in Cortex XDR Agent allows a local authenticated Windows user to create files in the software's internal program directory that prevents the Cortex XDR Agent from starting. The exceptional condition is persistent and prevents Cortex XDR Agent from starting when the software or machine is restarted. This issue impacts: Cortex XDR Agent 5.0 versions earlier than 5.0.10; Cortex XDR Agent 6.1 versions earlier than 6.1.7; Cortex XDR Agent 7.0 versions earlier than 7.0.3; Cortex XDR Agent 7.1 versions earlier than 7.1.2.

    Published: 9 Dec 2020
    7.1
    High

    CVE-2020-7776

    Last Modified: 21 Nov 2024

    This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html output from an excel file by adding a comment on any cell. The root cause of this issue is within the HTML writer where user comments are concatenated as part of link and this is returned as HTML. A fix for this issue is available on commit 0ed5b800be2136bcb8fa9c1bdf59abc957a98845/master branch.

    Published: 9 Dec 2020
    8.2
    High

    CVE-2020-7787

    Last Modified: 21 Nov 2024

    This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to treat an attacker-generated JWT token as authentic. The logical defect is caused by how the nonce, session and refresh values are stored in the browser local storage or session storage. Each key is automatically appended by ||. When the received nonce and session keys are generated, the list of values is stored in the browser storage, separated by ||, with || always appended to the end of the list. Since || will always be the last 2 characters of the stored values, an empty string ("") will always be in the list of the valid values. Therefore, if an empty session parameter is provided in the callback URL, and a specially-crafted JWT token contains an nonce value of "" (empty string), then adal.js will consider the JWT token as authentic.

    Published: 9 Dec 2020
    9.8
    Critical

    CVE-2020-17529

    Last Modified: 13 Feb 2025

    Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.

    Published: 9 Dec 2020
    9.1
    Critical

    CVE-2020-17528

    Last Modified: 13 Feb 2025

    Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-26836

    Last Modified: 21 Nov 2024

    SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.

    Published: 9 Dec 2020
    9.1
    Critical

    CVE-2020-26837

    Last Modified: 21 Nov 2024

    SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.

    Published: 9 Dec 2020
    9.1
    Critical

    CVE-2020-26838

    Last Modified: 21 Nov 2024

    SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.

    Published: 9 Dec 2020
    7.6
    High

    CVE-2020-26832

    Last Modified: 21 Nov 2024

    SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.

    Published: 9 Dec 2020
    6.1
    Medium

    CVE-2020-26835

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Dec 2020
    5.4
    Medium

    CVE-2020-26834

    Last Modified: 21 Nov 2024

    SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a user whose name is identical to the truncated username for whom the SAML bearer token was issued.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-26826

    Last Modified: 21 Nov 2024

    Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.

    Published: 9 Dec 2020
    6.4
    Medium

    CVE-2020-26828

    Last Modified: 21 Nov 2024

    SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execute scripts. The execution of a payload (script) on target machine could be used to steal and modify the data available in the spreadsheet

    Published: 9 Dec 2020
    7.9
    High

    CVE-2020-26261

    Last Modified: 21 Nov 2024

    jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15

    Published: 9 Dec 2020
    9.6
    Critical

    CVE-2020-26831

    Last Modified: 21 Nov 2024

    SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic privileges can inject some arbitrary XML entities leading to internal file disclosure, internal directories disclosure, Server-Side Request Forgery (SSRF) and denial-of-service (DoS).

    Published: 9 Dec 2020
    8.1
    High

    CVE-2020-26830

    Last Modified: 21 Nov 2024

    SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience Monitoring configuration, obtain details about the configured SAP Solution Manager agents, Deploy a malicious User Experience Monitoring script.

    Published: 9 Dec 2020
    —
    Unknown

    CVE-2020-21009

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Dec 2020
    10
    Critical

    CVE-2020-26829

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.

    Published: 9 Dec 2020
    4.5
    Medium

    CVE-2020-26816

    Last Modified: 21 Nov 2024

    SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys because of missing encryption and get some application data and client credentials of adjacent systems. This highly impacts Confidentiality as information disclosed could contain client credentials of adjacent systems.

    Published: 9 Dec 2020
    6.4
    Medium

    CVE-2020-26260

    Last Modified: 21 Nov 2024

    BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server side requests and/or have access to a wider scope of files within the BookStack file storage locations. The issue was addressed in BookStack v0.30.5. As a workaround, page edit permissions could be limited to only those that are trusted until you can upgrade.

    Published: 9 Dec 2020
    9.8
    Critical

    CVE-2020-29659

    Last Modified: 21 Nov 2024

    A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.

    Published: 9 Dec 2020
    7.8
    High

    CVE-2020-25199

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow vulnerability exists within the WECON LeviStudioU Release Build 2019-09-21 and prior when processing project files. Opening a specially crafted project file could allow an attacker to exploit and execute code under the privileges of the application.

    Published: 9 Dec 2020
    7.2
    High

    CVE-2020-23520

    Last Modified: 21 Nov 2024

    imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

    Published: 9 Dec 2020
    4.5
    Medium

    CVE-2020-35508

    Last Modified: 21 Nov 2024

    A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

    Published: 9 Dec 2020
    6.5
    Medium

    CVE-2020-7337

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.

    Published: 9 Dec 2020
    9.1
    Critical

    CVE-2020-29657

    Last Modified: 21 Nov 2024

    In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-29655

    Last Modified: 21 Nov 2024

    An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker might be able to influence the appearance of the login page, aka text injection.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-29656

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=General&special_cgi=get_language makes it possible to reach "unknown functionality" in a "known to be easy" manner via an unspecified "public exploit."

    Published: 9 Dec 2020
    3.7
    Low

    CVE-2020-8284

    Last Modified: 16 Apr 2026

    A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

    Published: 9 Dec 2020
    7.5
    High

    CVE-2020-8285

    Last Modified: 16 Apr 2026

    curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

    Published: 9 Dec 2020