CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-29572

    Last Modified: 21 Nov 2024

    app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.

    Published: 5 Dec 2020
    7.8
    High

    CVE-2020-28950

    Last Modified: 21 Nov 2024

    The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.

    Published: 4 Dec 2020
    4.8
    Medium

    CVE-2020-25449

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-25464

    Last Modified: 21 Nov 2024

    Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-25465

    Last Modified: 21 Nov 2024

    Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).

    Published: 4 Dec 2020
    9.8
    Critical

    CVE-2020-25462

    Last Modified: 21 Nov 2024

    Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-25461

    Last Modified: 21 Nov 2024

    Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-25463

    Last Modified: 21 Nov 2024

    Invalid Memory Access in fxUTF8Decode at moddable/xs/sources/xsCommon.c:916 in Moddable SDK before OS200908 causes a denial of service (SEGV).

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-27408

    Last Modified: 21 Nov 2024

    OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

    Published: 4 Dec 2020
    6.1
    Medium

    CVE-2020-27409

    Last Modified: 21 Nov 2024

    OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.

    Published: 4 Dec 2020
    7.5
    High

    CVE-2020-5675

    Last Modified: 21 Nov 2024

    Out-of-bounds read vulnerability in GT21 model of GOT2000 series (GT2107-WTBD V01.39.000 and earlier, GT2107-WTSD V01.39.000 and earlier, GT2104-RTBD V01.39.000 and earlier, GT2104-PMBD V01.39.000 and earlier, and GT2103-PMBD V01.39.000 and earlier), GS21 model of GOT series (GS2110-WTBD V01.39.000 and earlier, GS2107-WTBD V01.39.000 and earlier, GS2110-WTBD-N V01.39.000 and earlier, and GS2107-WTBD-N V01.39.000 and earlier), and Tension Controller LE7-40GU-L series (LE7-40GU-L Screen package data for CC-Link IEF Basic V1.00, LE7-40GU-L Screen package data for MODBUS/TCP V1.00, and LE7-40GU-L Screen package data for SLMP V1.00) allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted packet. As a result, deterioration of communication performance or a denial-of-service (DoS) condition of the TCP communication functions of the products may occur.

    Published: 4 Dec 2020
    5.5
    Medium

    CVE-2020-29561

    Last Modified: 21 Nov 2024

    An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.

    Published: 4 Dec 2020
    6.8
    Medium

    CVE-2020-27348

    Last Modified: 21 Nov 2024

    In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.

    Published: 4 Dec 2020
    5.9
    Medium

    CVE-2020-27822

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw allows an attacker to impact the availability of the server. The highest threat from this vulnerability is to system availability.

    Published: 4 Dec 2020
    4.4
    Medium

    CVE-2020-29660

    Last Modified: 21 Nov 2024

    A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

    Published: 4 Dec 2020
    7.8
    High

    CVE-2020-29661

    Last Modified: 21 Nov 2024

    A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

    Published: 4 Dec 2020
    6.8
    Medium

    CVE-2020-26248

    Last Modified: 21 Nov 2024

    In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-23736

    Last Modified: 21 Nov 2024

    There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs to cause computer crashes (BSOD).

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-23738

    Last Modified: 21 Nov 2024

    There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a constructed program to cause a computer crash (BSOD)

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-23741

    Last Modified: 21 Nov 2024

    In AnyView (network police) network monitoring software 4.6.0.1, there is a local denial of service vulnerability in AnyView, attackers can use a constructed program to cause a computer crash (BSOD).

    Published: 3 Dec 2020
    7.8
    High

    CVE-2020-23740

    Last Modified: 21 Nov 2024

    In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges.

    Published: 3 Dec 2020
    7.8
    High

    CVE-2020-28175

    Last Modified: 21 Nov 2024

    There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-23727

    Last Modified: 21 Nov 2024

    There is a local denial of service vulnerability in the Antiy Zhijia Terminal Defense System 5.0.2.10121559 and an attacker can cause a computer crash (BSOD).

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-23726

    Last Modified: 21 Nov 2024

    There is a local denial of service vulnerability in Wise Care 365 5.5.4, attackers can cause computer crash (BSOD).

    Published: 3 Dec 2020
    8.8
    High

    CVE-2020-13525

    Last Modified: 21 Nov 2024

    The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 3 Dec 2020
    5.5
    Medium

    CVE-2020-13524

    Last Modified: 21 Nov 2024

    An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.

    Published: 3 Dec 2020
    7.8
    High

    CVE-2020-23735

    Last Modified: 21 Nov 2024

    In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges

    Published: 3 Dec 2020
    8.1
    High

    CVE-2020-25693

    Last Modified: 21 Nov 2024

    A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.

    Published: 3 Dec 2020
    8.1
    High

    CVE-2020-28251

    Last Modified: 21 Nov 2024

    NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier has a sensor escalated privileges vulnerability that can be exploited to provide someone with administrative access to a sensor, with credentials to invoke a command to provide root access to the operating system. The attacker must complete a straightforward password-cracking exercise.

    Published: 3 Dec 2020
    7.8
    High

    CVE-2020-13542

    Last Modified: 21 Nov 2024

    A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or replace DLL files loaded by the service, both which get executed by a service thus executing arbitrary commands with System privileges.

    Published: 3 Dec 2020
    8.8
    High

    CVE-2020-13531

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger the reuse of a freed memory which can result in further memory corruption and arbitrary code execution. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

    Published: 3 Dec 2020
    2.7
    Low

    CVE-2020-28923

    Last Modified: 21 Nov 2024

    An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.

    Published: 3 Dec 2020
    7.2
    High

    CVE-2020-28939

    Last Modified: 21 Nov 2024

    OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

    Published: 3 Dec 2020
    5.4
    Medium

    CVE-2020-28938

    Last Modified: 21 Nov 2024

    OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.

    Published: 3 Dec 2020
    5.3
    Medium

    CVE-2020-2323

    Last Modified: 21 Nov 2024

    Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-2324

    Last Modified: 21 Nov 2024

    Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 3 Dec 2020
    8.1
    High

    CVE-2020-2321

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.

    Published: 3 Dec 2020
    9.8
    Critical

    CVE-2020-2320

    Last Modified: 21 Nov 2024

    Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-2322

    Last Modified: 21 Nov 2024

    Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-28937

    Last Modified: 21 Nov 2024

    OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

    Published: 3 Dec 2020
    9.8
    Critical

    CVE-2020-6017

    Last Modified: 21 Nov 2024

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

    Published: 3 Dec 2020
    7.8
    High

    CVE-2020-6021

    Last Modified: 21 Nov 2024

    Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted DLL in the repair folder which will run with the Endpoint client’s privileges.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-6111

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller Systems Series B FRN 16.000, Series B FRN 15.002, Series B FRN 15.000, Series B FRN 14.000, Series B FRN 13.000, Series B FRN 12.000, Series B FRN 11.000 and Series B FRN 10.000. A specially crafted packet can cause a major error, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-5680

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in EC-CUBE versions from 3.0.5 to 3.0.18 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vector.

    Published: 3 Dec 2020
    6.1
    Medium

    CVE-2020-5677

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in GROWI v4.0.0 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

    Published: 3 Dec 2020
    6.1
    Medium

    CVE-2020-5679

    Last Modified: 21 Nov 2024

    Improper restriction of rendered UI layers or frames in EC-CUBE versions from 3.0.0 to 3.0.18 leads to clickjacking attacks. If a user accesses a specially crafted page while logged into the administrative page, unintended operations may be conducted.

    Published: 3 Dec 2020
    6.1
    Medium

    CVE-2020-5678

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in GROWI v3.8.1 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

    Published: 3 Dec 2020
    6.1
    Medium

    CVE-2020-5638

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.

    Published: 3 Dec 2020
    7.5
    High

    CVE-2020-5676

    Last Modified: 21 Nov 2024

    GROWI v4.1.3 and earlier allow remote attackers to obtain information which is not allowed to access via unspecified vectors.

    Published: 3 Dec 2020
    7.7
    High

    CVE-2020-26246

    Last Modified: 21 Nov 2024

    Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions.

    Published: 3 Dec 2020