CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-27558

    Last Modified: 21 Nov 2024

    Use of an undocumented user in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to view the video stream.

    Published: 17 Nov 2020
    4.6
    Medium

    CVE-2020-25746

    Last Modified: 21 Nov 2024

    QED ResourceXpress Qubi3 devices before 1.40.9 could allow a local attacker (with physical access to the device) to obtain sensitive information via the debug interface (keystrokes over a USB cable), aka wireless password visibility.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-28687

    Last Modified: 21 Nov 2024

    The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-28688

    Last Modified: 21 Nov 2024

    The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.

    Published: 17 Nov 2020
    5.4
    Medium

    CVE-2020-28647

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-7841

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://

    Published: 17 Nov 2020
    8.1
    High

    CVE-2020-25716

    Last Modified: 21 Nov 2024

    A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administrator. This is the affect of an incomplete fix for CVE-2020-10783. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before cfme 5.11.10.1 are affected

    Published: 17 Nov 2020
    9.1
    Critical

    CVE-2020-27130

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to download arbitrary files from the affected device.

    Published: 17 Nov 2020
    8.1
    High

    CVE-2020-27131

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.

    Published: 17 Nov 2020
    7.4
    High

    CVE-2020-27125

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could exploit this vulnerability by viewing source code. A successful exploit could allow the attacker to view static credentials, which the attacker could use to carry out further attacks.

    Published: 17 Nov 2020
    7.8
    High

    CVE-2020-27192

    Last Modified: 21 Nov 2024

    BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to inject code into ForkLift. This would allow the attacker to run malicious code with escalated privileges through ForkLift's helper tool.

    Published: 17 Nov 2020
    7.8
    High

    CVE-2020-15349

    Last Modified: 21 Nov 2024

    BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permissions.

    Published: 17 Nov 2020
    4.8
    Medium

    CVE-2020-25833

    Last Modified: 21 Nov 2024

    Persistent cross-Site Scripting vulnerability on Micro Focus IDOL product, affecting all version prior to version 12.7. The vulnerability could be exploited to perform Persistent XSS attack.

    Published: 17 Nov 2020
    5.4
    Medium

    CVE-2020-25832

    Last Modified: 21 Nov 2024

    Reflected Cross Site scripting vulnerability on Micro Focus Filr product, affecting version 4.2.1. The vulnerability could be exploited to perform Reflected XSS attack.

    Published: 17 Nov 2020
    9.8
    Critical

    CVE-2020-11851

    Last Modified: 21 Nov 2024

    Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-11860

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS)

    Published: 17 Nov 2020
    5.4
    Medium

    CVE-2020-25834

    Last Modified: 21 Nov 2024

    Cross-Site Scripting vulnerability on Micro Focus ArcSight Logger product, affecting version 7.1. The vulnerability could be remotely exploited resulting in Cross-Site Scripting (XSS).

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-13354

    Last Modified: 21 Nov 2024

    A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied values resulting in high CPU usage. Affected versions are: >=12.6, <13.3.9.

    Published: 17 Nov 2020
    3.7
    Low

    CVE-2020-13352

    Last Modified: 21 Nov 2024

    Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    2.5
    Low

    CVE-2020-13353

    Last Modified: 21 Nov 2024

    When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

    Published: 17 Nov 2020
    4.7
    Medium

    CVE-2020-13358

    Last Modified: 21 Nov 2024

    A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    5.3
    Medium

    CVE-2020-26406

    Last Modified: 21 Nov 2024

    Certain SAST CiConfiguration information could be viewed by unauthorized users in GitLab EE starting with 13.3. This information was exposed through GraphQL to non-members of public projects with repository visibility restricted as well as guest members on private projects. Affected versions are: >=13.3, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16015

    Last Modified: 21 Nov 2024

    Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16020

    Last Modified: 21 Nov 2024

    Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16026

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-16033

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-26951

    Last Modified: 21 Nov 2024

    A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-26961

    Last Modified: 21 Nov 2024

    When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-26965

    Last Modified: 21 Nov 2024

    Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    9.6
    Critical

    CVE-2020-16014

    Last Modified: 21 Nov 2024

    Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 17 Nov 2020
    9.6
    Critical

    CVE-2020-16018

    Last Modified: 21 Nov 2024

    Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 17 Nov 2020
    7.5
    High

    CVE-2020-16021

    Last Modified: 21 Nov 2024

    Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16022

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16023

    Last Modified: 21 Nov 2024

    Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 17 Nov 2020
    9.6
    Critical

    CVE-2020-16024

    Last Modified: 21 Nov 2024

    Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-16027

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a crafted Chrome Extension.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16028

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16029

    Last Modified: 21 Nov 2024

    Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-16031

    Last Modified: 21 Nov 2024

    Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-16034

    Last Modified: 21 Nov 2024

    Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16035

    Last Modified: 21 Nov 2024

    Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-16036

    Last Modified: 21 Nov 2024

    Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-25660

    Last Modified: 21 Nov 2024

    A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-26960

    Last Modified: 21 Nov 2024

    If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    6.5
    Medium

    CVE-2020-26966

    Last Modified: 21 Nov 2024

    Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-26968

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

    Published: 17 Nov 2020
    4.3
    Medium

    CVE-2020-16012

    Last Modified: 21 Nov 2024

    Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 17 Nov 2020
    8.8
    High

    CVE-2020-16019

    Last Modified: 21 Nov 2024

    Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass noexec restrictions via a malicious file.

    Published: 17 Nov 2020
    9.6
    Critical

    CVE-2020-16025

    Last Modified: 21 Nov 2024

    Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 17 Nov 2020
    6.1
    Medium

    CVE-2020-16030

    Last Modified: 21 Nov 2024

    Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

    Published: 17 Nov 2020