CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-15681

    Last Modified: 21 Nov 2024

    In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.

    Published: 27 Nov 2020
    6.1
    Medium

    CVE-2017-15682

    Last Modified: 21 Nov 2024

    In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.

    Published: 27 Nov 2020
    8.6
    High

    CVE-2017-15683

    Last Modified: 21 Nov 2024

    In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

    Published: 27 Nov 2020
    7.5
    High

    CVE-2017-15684

    Last Modified: 21 Nov 2024

    Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.

    Published: 27 Nov 2020
    8.6
    High

    CVE-2017-15685

    Last Modified: 21 Nov 2024

    Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

    Published: 27 Nov 2020
    6.1
    Medium

    CVE-2017-15686

    Last Modified: 21 Nov 2024

    Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2020-25014

    Last Modified: 12 Dec 2024

    A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.

    Published: 27 Nov 2020
    3.7
    Low

    CVE-2020-27746

    Last Modified: 21 Nov 2024

    Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2020-27745

    Last Modified: 21 Nov 2024

    Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.

    Published: 27 Nov 2020
    6.3
    Medium

    CVE-2020-7780

    Last Modified: 21 Nov 2024

    This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by randomTokenCsrfProtection could be bypassed with an empty X-XSRF-TOKEN header and an empty XSRF-TOKEN cookie.

    Published: 27 Nov 2020
    7.5
    High

    CVE-2019-19878

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.

    Published: 27 Nov 2020
    5.3
    Medium

    CVE-2019-19877

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive information outside the working directory via Directory Traversal attacks against AprolSqlServer, a different vulnerability than CVE-2019-16357.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2019-19876

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2019-19875

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus executes with root privileges, a different vulnerability than CVE-2019-16364.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2019-19874

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.

    Published: 27 Nov 2020
    7.5
    High

    CVE-2019-19873

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the AprolSqlServer DBMS by bypassing authentication, a different vulnerability than CVE-2019-16356 and CVE-2019-9983.

    Published: 27 Nov 2020
    5.3
    Medium

    CVE-2020-29138

    Last Modified: 21 Nov 2024

    Incorrect Access Control in the configuration backup path in SAGEMCOM F@ST3486 NET DOCSIS 3.0, software NET_4.109.0, allows remote unauthenticated users to download the router configuration file via the /backupsettings.conf URI, when any valid session is running.

    Published: 27 Nov 2020
    9.8
    Critical

    CVE-2019-19872

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a different vulnerability than CVE-2019-16364.

    Published: 27 Nov 2020
    7.5
    High

    CVE-2019-19869

    Last Modified: 21 Nov 2024

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by using the IosHttp service and the JSON interface.

    Published: 27 Nov 2020
    5.5
    Medium

    CVE-2020-25738

    Last Modified: 21 Nov 2024

    CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.

    Published: 27 Nov 2020
    5.4
    Medium

    CVE-2020-29144

    Last Modified: 21 Nov 2024

    In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins' browsers by using the beef framework.

    Published: 27 Nov 2020
    5.4
    Medium

    CVE-2020-29145

    Last Modified: 21 Nov 2024

    In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins' browsers by using the beef framework.

    Published: 27 Nov 2020
    6.5
    Medium

    CVE-2020-29136

    Last Modified: 21 Nov 2024

    In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

    Published: 27 Nov 2020
    6.1
    Medium

    CVE-2020-29137

    Last Modified: 21 Nov 2024

    cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).

    Published: 27 Nov 2020
    4.1
    Medium

    CVE-2020-29135

    Last Modified: 21 Nov 2024

    cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).

    Published: 27 Nov 2020
    6.1
    Medium

    CVE-2020-29133

    Last Modified: 21 Nov 2024

    jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter.

    Published: 27 Nov 2020
    4.8
    Medium

    CVE-2020-27218

    Last Modified: 21 Nov 2024

    In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the application, then a subsequent request on the same connection will see that body prepended to its body. The attacker will not see any data but may inject data into the body of the subsequent request.

    Published: 27 Nov 2020
    5.4
    Medium

    CVE-2020-12262

    Last Modified: 21 Nov 2024

    Intelbras TIP200 60.61.75.15, TIP200LITE 60.61.75.15, and TIP300 65.61.75.15 devices allow /cgi-bin/cgiServer.exx?page= XSS.

    Published: 26 Nov 2020
    8.8
    High

    CVE-2020-26936

    Last Modified: 21 Nov 2024

    Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack.

    Published: 26 Nov 2020
    3.7
    Low

    CVE-2020-29042

    Last Modified: 21 Nov 2024

    An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.

    Published: 26 Nov 2020
    7.5
    High

    CVE-2020-29043

    Last Modified: 21 Nov 2024

    An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.

    Published: 26 Nov 2020
    —
    Unknown

    CVE-2020-29065

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2020. Notes: none

    Published: 26 Nov 2020
    5.3
    Medium

    CVE-2020-13886

    Last Modified: 21 Nov 2024

    Intelbras TIP 200 60.61.75.15, TIP 200 LITE 60.61.75.15, and TIP 300 65.61.75.22 devices allow cgi-bin/cgiServer.exx?page=../ Directory Traversal.

    Published: 26 Nov 2020
    4.3
    Medium

    CVE-2020-27663

    Last Modified: 21 Nov 2024

    In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.).

    Published: 26 Nov 2020
    4.3
    Medium

    CVE-2020-27662

    Last Modified: 21 Nov 2024

    In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.).

    Published: 26 Nov 2020
    7.5
    High

    CVE-2020-27207

    Last Modified: 21 Nov 2024

    Zetetic SQLCipher 4.x before 4.4.1 has a use-after-free, related to sqlcipher_codec_pragma and sqlite3Strlen30 in sqlite3.c. A remote denial of service attack can be performed. For example, a SQL injection can be used to execute the crafted SQL command sequence. After that, some unexpected RAM data is read.

    Published: 26 Nov 2020
    7.3
    High

    CVE-2020-7778

    Last Modified: 21 Nov 2024

    This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

    Published: 26 Nov 2020
    5.3
    Medium

    CVE-2020-7779

    Last Modified: 21 Nov 2024

    All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.

    Published: 26 Nov 2020
    9.8
    Critical

    CVE-2020-29128

    Last Modified: 21 Nov 2024

    petl before 1.68, in some configurations, allows resolution of entities in an XML document.

    Published: 26 Nov 2020
    9.8
    Critical

    CVE-2020-27251

    Last Modified: 21 Nov 2024

    A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.

    Published: 26 Nov 2020
    7.5
    High

    CVE-2020-27255

    Last Modified: 21 Nov 2024

    A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).

    Published: 26 Nov 2020
    7.5
    High

    CVE-2020-27253

    Last Modified: 21 Nov 2024

    A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device.

    Published: 26 Nov 2020
    5.3
    Medium

    CVE-2020-10770

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

    Published: 26 Nov 2020
    4.3
    Medium

    CVE-2020-29130

    Last Modified: 21 Nov 2024

    slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

    Published: 26 Nov 2020
    4.9
    Medium

    CVE-2020-14302

    Last Modified: 21 Nov 2024

    A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.

    Published: 26 Nov 2020
    4.3
    Medium

    CVE-2020-29129

    Last Modified: 21 Nov 2024

    ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

    Published: 26 Nov 2020
    7.5
    High

    CVE-2020-14190

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.

    Published: 25 Nov 2020
    8.8
    High

    CVE-2020-29074

    Last Modified: 21 Nov 2024

    scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.

    Published: 25 Nov 2020
    7.5
    High

    CVE-2020-14191

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.

    Published: 25 Nov 2020
    4.8
    Medium

    CVE-2020-29070

    Last Modified: 21 Nov 2024

    osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.

    Published: 25 Nov 2020