CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-25207

    Last Modified: 21 Nov 2024

    JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.

    Published: 16 Nov 2020
    7.5
    High

    CVE-2020-25013

    Last Modified: 21 Nov 2024

    JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler.

    Published: 16 Nov 2020
    5.3
    Medium

    CVE-2020-27624

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.

    Published: 16 Nov 2020
    5.3
    Medium

    CVE-2020-27625

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.

    Published: 16 Nov 2020
    5.3
    Medium

    CVE-2020-27626

    Last Modified: 21 Nov 2024

    JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.

    Published: 16 Nov 2020
    7.5
    High

    CVE-2020-25209

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.3.6638, improper access control for some subresources leads to information disclosure via the REST API.

    Published: 16 Nov 2020
    3.3
    Low

    CVE-2020-24366

    Last Modified: 21 Nov 2024

    Sensitive information could be disclosed in the JetBrains YouTrack application before 2020.2.0 for Android via application backups.

    Published: 16 Nov 2020
    6.1
    Medium

    CVE-2020-27459

    Last Modified: 21 Nov 2024

    Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.

    Published: 16 Nov 2020
    5.3
    Medium

    CVE-2020-25210

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2020.3.7955, an attacker could access workflow rules without appropriate access grants.

    Published: 16 Nov 2020
    6.5
    Medium

    CVE-2020-7773

    Last Modified: 21 Nov 2024

    This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md = require('markdown-it'); const reuslt_xss = md() .use(markdownItHighlightjs, { inline: true }) .render('console.log(42){.">js}'); console.log(reuslt_xss);

    Published: 16 Nov 2020
    5.6
    Medium

    CVE-2020-7765

    Last Modified: 21 Nov 2024

    This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

    Published: 16 Nov 2020
    4.8
    Medium

    CVE-2020-8897

    Last Modified: 21 Nov 2024

    A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.

    Published: 16 Nov 2020
    9.8
    Critical

    CVE-2020-5664

    Last Modified: 21 Nov 2024

    Deserialization of untrusted data vulnerability in XooNIps 3.49 and earlier allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Nov 2020
    5.4
    Medium

    CVE-2020-5663

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-5659

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the XooNIps 3.49 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Nov 2020
    5.4
    Medium

    CVE-2020-5662

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

    Published: 16 Nov 2020
    6.8
    Medium

    CVE-2020-28656

    Last Modified: 21 Nov 2024

    The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-28649

    Last Modified: 21 Nov 2024

    The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.

    Published: 16 Nov 2020
    6.4
    Medium

    CVE-2020-28650

    Last Modified: 21 Nov 2024

    The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-28648

    Last Modified: 21 Nov 2024

    Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.

    Published: 16 Nov 2020
    9.8
    Critical

    CVE-2020-28642

    Last Modified: 21 Nov 2024

    In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.

    Published: 16 Nov 2020
    7.2
    High

    CVE-2020-2490

    Last Modified: 21 Nov 2024

    If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

    Published: 16 Nov 2020
    7.2
    High

    CVE-2020-2492

    Last Modified: 21 Nov 2024

    If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

    Published: 16 Nov 2020
    7.5
    High

    CVE-2020-5666

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption vulnerability in MELSEC iQ-R Series CPU Modules (R00/01/02CPU Firmware versions from '05' to '19' and R04/08/16/32/120(EN)CPU Firmware versions from '35' to '51') allows a remote attacker to cause an error in a CPU unit via a specially crafted HTTP packet, which may lead to a denial-of-service (DoS) condition in execution of the program and its communication.

    Published: 16 Nov 2020
    8.1
    High

    CVE-2020-8259

    Last Modified: 21 Nov 2024

    Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

    Published: 16 Nov 2020
    4.4
    Medium

    CVE-2020-8152

    Last Modified: 21 Nov 2024

    Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-8270

    Last Modified: 21 Nov 2024

    An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-8269

    Last Modified: 21 Nov 2024

    An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

    Published: 16 Nov 2020
    8.8
    High

    CVE-2020-8273

    Last Modified: 21 Nov 2024

    Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

    Published: 16 Nov 2020
    7.5
    High

    CVE-2020-8272

    Last Modified: 21 Nov 2024

    Authentication Bypass resulting in exposure of SD-WAN functionality in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

    Published: 16 Nov 2020
    9.8
    Critical

    CVE-2020-8271

    Last Modified: 21 Nov 2024

    Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

    Published: 16 Nov 2020
    4.3
    Medium

    CVE-2020-25724

    Last Modified: 21 Nov 2024

    A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected.

    Published: 16 Nov 2020
    5.8
    Medium

    CVE-2020-28915

    Last Modified: 21 Nov 2024

    A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

    Published: 16 Nov 2020
    2.4
    Low

    CVE-2019-19561

    Last Modified: 21 Nov 2024

    A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.

    Published: 15 Nov 2020
    2.4
    Low

    CVE-2019-19557

    Last Modified: 21 Nov 2024

    A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.

    Published: 15 Nov 2020
    2.4
    Low

    CVE-2019-19563

    Last Modified: 21 Nov 2024

    A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.

    Published: 15 Nov 2020
    4.6
    Medium

    CVE-2019-19560

    Last Modified: 21 Nov 2024

    An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.

    Published: 15 Nov 2020
    4.6
    Medium

    CVE-2019-19556

    Last Modified: 21 Nov 2024

    An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information.

    Published: 15 Nov 2020
    4.6
    Medium

    CVE-2019-19562

    Last Modified: 21 Nov 2024

    An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.

    Published: 15 Nov 2020
    7.5
    High

    CVE-2020-28268

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in 'controlled-merge' versions 1.0.0 through 1.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

    Published: 15 Nov 2020
    7.5
    High

    CVE-2020-7772

    Last Modified: 21 Nov 2024

    This affects the package doc-path before 2.1.2.

    Published: 15 Nov 2020
    7.1
    High

    CVE-2020-28407

    Last Modified: 21 Nov 2024

    In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

    Published: 14 Nov 2020
    7.8
    High

    CVE-2020-15481

    Last Modified: 21 Nov 2024

    An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys drivers. This issue is fixed in BurnInTest v9.2, PerformanceTest v10.0 Build 1009, OSForensics v8.0.

    Published: 13 Nov 2020
    9.8
    Critical

    CVE-2020-28638

    Last Modified: 21 Nov 2024

    ask_password in Tomb 2.0 through 2.7 returns a warning when pinentry-curses is used and $DISPLAY is non-empty, causing affected users' files to be encrypted with "tomb {W] Detected DISPLAY, but only pinentry-curses is found." as the encryption key.

    Published: 13 Nov 2020
    8.8
    High

    CVE-2020-12313

    Last Modified: 21 Nov 2024

    Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 13 Nov 2020
    9.8
    Critical

    CVE-2020-12338

    Last Modified: 21 Nov 2024

    Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 13 Nov 2020
    6.7
    Medium

    CVE-2020-0599

    Last Modified: 21 Nov 2024

    Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 Nov 2020
    7.8
    High

    CVE-2020-5796

    Last Modified: 21 Nov 2024

    Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.

    Published: 13 Nov 2020
    9.8
    Critical

    CVE-2020-13638

    Last Modified: 21 Nov 2024

    lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

    Published: 13 Nov 2020
    7.5
    High

    CVE-2020-27217

    Last Modified: 21 Nov 2024

    In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link establishment. While the AMQP 1.0 protocol explicitly disallows a peer to send such messages, a hand crafted AMQP 1.0 client could exploit this behavior in order to send a message of unlimited size to the adapter, eventually causing the adapter to fail with an out of memory exception.

    Published: 13 Nov 2020