CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2020-25406

    Last Modified: 21 Nov 2024

    app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.

    Published: 18 Nov 2020
    8.8
    High

    CVE-2020-24297

    Last Modified: 21 Nov 2024

    httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST requests to the endpoint /admin/powerline. Fixed version: TL-WPA4220(EU)_V4_201023

    Published: 18 Nov 2020
    6.5
    Medium

    CVE-2020-28005

    Last Modified: 21 Nov 2024

    httpd on TP-Link TL-WPA4220 devices (hardware versions 2 through 4) allows remote authenticated users to trigger a buffer overflow (causing a denial of service) by sending a POST request to the /admin/syslog endpoint. Fixed version: TL-WPA4220(EU)_V4_201023

    Published: 18 Nov 2020
    6.1
    Medium

    CVE-2020-26884

    Last Modified: 21 Nov 2024

    RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

    Published: 18 Nov 2020
    9.8
    Critical

    CVE-2020-6016

    Last Modified: 21 Nov 2024

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-Based Buffer Underflow and a free() of memory not from the heap, resulting in a memory corruption and probably even a remote code execution.

    Published: 18 Nov 2020
    8.1
    High

    CVE-2020-7562

    Last Modified: 29 May 2026

    A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.

    Published: 18 Nov 2020
    8.8
    High

    CVE-2020-7564

    Last Modified: 29 May 2026

    A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.

    Published: 18 Nov 2020
    8.8
    High

    CVE-2020-7563

    Last Modified: 29 May 2026

    A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.

    Published: 18 Nov 2020
    5.4
    Medium

    CVE-2020-28361

    Last Modified: 21 Nov 2024

    Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular use of remove_hf in Sippy Softswitch may allow skilled attacker having a valid credential in the system to disrupt internal call start/duration accounting mechanisms leading potentially to a loss of revenue.

    Published: 18 Nov 2020
    4.8
    Medium

    CVE-2020-24723

    Last Modified: 27 Dec 2024

    Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.

    Published: 18 Nov 2020
    6.5
    Medium

    CVE-2020-28917

    Last Modified: 21 Nov 2024

    An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be saved.

    Published: 18 Nov 2020
    7.8
    High

    CVE-2020-29367

    Last Modified: 25 Apr 2025

    blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.

    Published: 18 Nov 2020
    3.9
    Low

    CVE-2020-29443

    Last Modified: 21 Nov 2024

    ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

    Published: 18 Nov 2020
    0
    Low

    CVE-2021-0384

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Nov 2020
    2.7
    Low

    CVE-2020-14341

    Last Modified: 21 Nov 2024

    The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information about hosts and ports which they do not have access to scan directly.

    Published: 18 Nov 2020
    7
    High

    CVE-2020-28912

    Last Modified: 21 Nov 2024

    With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

    Published: 18 Nov 2020
    9.8
    Critical

    CVE-2020-28183

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-28092

    Last Modified: 21 Nov 2024

    PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=

    Published: 17 Nov 2020
    7.1
    High

    CVE-2020-28914

    Last Modified: 21 Nov 2024

    An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container breakout situation, a malicious guest can potentially modify or delete files/directories expected to be read-only.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-26553

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-26552

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

    Published: 17 Nov 2020
    8
    High

    CVE-2020-26216

    Last Modified: 21 Nov 2024

    TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities have been detected in Fluid: 1. TagBasedViewHelper allowed XSS through maliciously crafted additionalAttributes arrays by creating keys with attribute-closing quotes followed by HTML. When rendering such attributes, TagBuilder would not escape the keys. 2. ViewHelpers which used the CompileWithContentArgumentAndRenderStatic trait, and which declared escapeOutput = false, would receive the content argument in unescaped format. 3. Subclasses of AbstractConditionViewHelper would receive the then and else arguments in unescaped format. Update to versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 or 2.6.10 of this typo3fluid/fluid package that fix the problem described. More details are available in the linked advisory.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-26551

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-26550

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-26549

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-26548

    Last Modified: 21 Nov 2024

    An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-28130

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-28129

    Last Modified: 22 Dec 2025

    Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-25890

    Last Modified: 21 Nov 2024

    The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-25988

    Last Modified: 21 Nov 2024

    UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' which leaks the credentials of 'admin', provided that the attacker is network adjacent.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-28136

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-28133

    Last Modified: 21 Nov 2024

    An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-28140

    Last Modified: 21 Nov 2024

    SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-28139

    Last Modified: 21 Nov 2024

    SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail field in offer.php.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-28138

    Last Modified: 21 Nov 2024

    SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

    Published: 17 Nov 2020
    7.1
    High

    CVE-2020-26405

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-13349

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab EE affecting all versions starting from 8.12. A regular expression related to a file path resulted in the Advanced Search feature susceptible to catastrophic backtracking. Affected versions are >=8.12, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    5.7
    Medium

    CVE-2020-13348

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab EE affecting all versions starting from 10.2. Required CODEOWNERS approval could be bypassed by targeting a branch without the CODEOWNERS file. Affected versions are >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-25400

    Last Modified: 21 Nov 2024

    Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token.

    Published: 17 Nov 2020
    3.1
    Low

    CVE-2020-13350

    Last Modified: 21 Nov 2024

    CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

    Published: 17 Nov 2020
    5.4
    Medium

    CVE-2020-26701

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inject malicious web scripts or HTML Injection payloads via the Description parameter.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-13351

    Last Modified: 21 Nov 2024

    Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

    Published: 17 Nov 2020
    7.8
    High

    CVE-2020-13958

    Last Modified: 21 Nov 2024

    A vulnerability in Apache OpenOffice scripting events allows an attacker to construct documents containing hyperlinks pointing to an executable on the target users file system. These hyperlinks can be triggered unconditionally. In fixed versions no internal protocol may be called from the document event handler and other hyperlinks require a control-click.

    Published: 17 Nov 2020
    7.2
    High

    CVE-2020-21665

    Last Modified: 21 Nov 2024

    In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-27553

    Last Modified: 21 Nov 2024

    In BASETech GE-131 BT-1837836 firmware 20180921, the web-server on the system is configured with the option “DocumentRoot /etc“. This allows an attacker with network access to the web-server to download any files from the “/etc” folder without authentication. No path traversal sequences are needed to exploit this vulnerability.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-27554

    Last Modified: 21 Nov 2024

    Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device.

    Published: 17 Nov 2020
    5.4
    Medium

    CVE-2020-25798

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-27555

    Last Modified: 21 Nov 2024

    Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.

    Published: 17 Nov 2020
    5.3
    Medium

    CVE-2020-27556

    Last Modified: 21 Nov 2024

    A predictable device ID in BASETech GE-131 BT-1837836 firmware 20180921 allows unauthenticated remote attackers to connect to the device.

    Published: 17 Nov 2020
    5.5
    Medium

    CVE-2020-27557

    Last Modified: 21 Nov 2024

    Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.

    Published: 17 Nov 2020