CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-11121

    Last Modified: 21 Nov 2024

    u'Possible buffer overflow in WIFI hal process due to usage of memcpy without checking length of destination buffer' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

    Published: 12 Nov 2020
    5.5
    Medium

    CVE-2020-11123

    Last Modified: 21 Nov 2024

    u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8009W, APQ8017, APQ8037, APQ8053, APQ8064AU, APQ8096, APQ8096AU, APQ8096SG, APQ8098, MDM8207, MDM9150, MDM9205, MDM9206, MDM9207, MDM9250, MDM9607, MDM9628, MDM9640, MDM9650, MDM9655, MSM8108, MSM8208, MSM8209, MSM8608, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8996SG, MSM8998, QCM4290, QCS405, QCS410, QCS4290, QCS603, QCS605, QCS610, QM215, QSM8250, QSM8350, SA415M, SA515M, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SC8180X, SC8180XP, SDA429W, SDA640, SDA660, SDA670, SDA845, SDA855, SDM1000, SDM429, SDM429W, SDM439, SDM450, SDM455, SDM630, SDM632, SDM636, SDM640, SDM660, SDM670, SDM710, SDM712, SDM830, SDM845, SDM850, SDW2500, SDX24, SDX50M, SDX55, SDX55M, SM4125, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR1120, SXR1130, SXR2130, SXR2130P, WCD9330

    Published: 12 Nov 2020
    4.8
    Medium

    CVE-2020-7333

    Last Modified: 21 Nov 2024

    Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML via the configuration wizard.

    Published: 12 Nov 2020
    7
    High

    CVE-2020-7332

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-7331

    Last Modified: 21 Nov 2024

    Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

    Published: 12 Nov 2020
    8.6
    High

    CVE-2020-7769

    Last Modified: 21 Nov 2024

    This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.

    Published: 12 Nov 2020
    8.6
    High

    CVE-2020-26070

    Last Modified: 21 Nov 2024

    A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource allocation when an affected device processes network traffic in software switching mode (punted). An attacker could exploit this vulnerability by sending specific streams of Layer 2 or Layer 3 protocol data units (PDUs) to an affected device. A successful exploit could cause the affected device to run out of buffer resources, which could make the device unable to process or forward traffic, resulting in a DoS condition. The device would need to be restarted to regain functionality.

    Published: 12 Nov 2020
    8.2
    High

    CVE-2020-2050

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authenticate as any user and gain access to restricted VPN network resources when the gateway or portal is configured to rely entirely on certificate-based authentication. Impacted features that use SSL VPN with client certificate verification are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN In configurations where client certificate verification is used in conjunction with other authentication methods, the protections added by the certificate check are ignored as a result of this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

    Published: 12 Nov 2020
    3.3
    Low

    CVE-2020-2048

    Last Modified: 21 Nov 2024

    An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when using the CLI in Palo Alto Networks PAN-OS software. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.2.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-2022

    Last Modified: 21 Nov 2024

    An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. This vulnerability allows an attacker to gain privileged access to the Panorama web interface. An attacker requires some knowledge of managed firewalls to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.17; PAN-OS 9.0 versions earlier than PAN-OS 9.0.11; PAN-OS 9.1 versions earlier than PAN-OS 9.1.5.

    Published: 12 Nov 2020
    7.2
    High

    CVE-2020-2000

    Last Modified: 21 Nov 2024

    An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.

    Published: 12 Nov 2020
    5.3
    Medium

    CVE-2020-1999

    Last Modified: 21 Nov 2024

    A vulnerability exists in the Palo Alto Network PAN-OS signature-based threat detection engine that allows an attacker to communicate with devices in the network in a way that is not analyzed for threats by sending data through specifically crafted TCP packets. This technique evades signature-based threat detection. This issue impacts: PAN-OS 8.1 versions earlier than 8.1.17; PAN-OS 9.0 versions earlier than 9.0.11; PAN-OS 9.1 versions earlier than 9.1.5; All versions of PAN-OS 7.1 and PAN-OS 8.0.

    Published: 12 Nov 2020
    6.1
    Medium

    CVE-2020-13954

    Last Modified: 13 Feb 2025

    By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.

    Published: 12 Nov 2020
    8.1
    High

    CVE-2020-25694

    Last Modified: 21 Nov 2024

    A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-28366

    Last Modified: 21 Nov 2024

    Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.

    Published: 12 Nov 2020
    5.5
    Medium

    CVE-2020-28916

    Last Modified: 21 Nov 2024

    hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-8277

    Last Modified: 30 Apr 2025

    A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.

    Published: 12 Nov 2020
    8.8
    High

    CVE-2020-25695

    Last Modified: 21 Nov 2024

    A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-25696

    Last Modified: 21 Nov 2024

    A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 12 Nov 2020
    5.4
    Medium

    CVE-2020-25706

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-28367

    Last Modified: 21 Nov 2024

    Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.

    Published: 12 Nov 2020
    7.5
    High

    CVE-2020-28362

    Last Modified: 21 Nov 2024

    Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service.

    Published: 12 Nov 2020
    7.8
    High

    CVE-2020-5992

    Last Modified: 21 Nov 2024

    NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.

    Published: 11 Nov 2020
    8
    High

    CVE-2020-26221

    Last Modified: 21 Nov 2024

    touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.

    Published: 11 Nov 2020
    3.5
    Low

    CVE-2020-26220

    Last Modified: 21 Nov 2024

    toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version 2.0.

    Published: 11 Nov 2020
    4.7
    Medium

    CVE-2020-26219

    Last Modified: 21 Nov 2024

    touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable. The issue is fixed in version 2.0.

    Published: 11 Nov 2020
    8
    High

    CVE-2020-26218

    Last Modified: 21 Nov 2024

    touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HTML payloads which could result in defacement, user redirection to a malicious webpage/website etc. The issue is patched in version 2.0.

    Published: 11 Nov 2020
    6.7
    Medium

    CVE-2020-8353

    Last Modified: 21 Nov 2024

    Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.

    Published: 11 Nov 2020
    6.4
    Medium

    CVE-2020-8354

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in the VariableServiceSmm driver in some Lenovo Notebook models may allow arbitrary code execution.

    Published: 11 Nov 2020
    2.4
    Low

    CVE-2020-8352

    Last Modified: 21 Nov 2024

    In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

    Published: 11 Nov 2020
    9.8
    Critical

    CVE-2020-5426

    Last Modified: 21 Nov 2024

    Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

    Published: 11 Nov 2020
    8.7
    High

    CVE-2020-15275

    Last Modified: 21 Nov 2024

    MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that SVG file on the wiki. Users are strongly advised to upgrade to a patched version. MoinMoin Wiki 1.9.11 has the necessary fixes and also contains other important fixes.

    Published: 11 Nov 2020
    7.5
    High

    CVE-2020-27523

    Last Modified: 21 Nov 2024

    Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which leads to a denial of service.

    Published: 11 Nov 2020
    7.1
    High

    CVE-2020-27524

    Last Modified: 21 Nov 2024

    On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.

    Published: 11 Nov 2020
    7.2
    High

    CVE-2020-4685

    Last Modified: 21 Nov 2024

    A low level user of IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 who has Administration rights to the server where the application is installed, can escalate their privilege from Low level to Super Admin and gain access to Create/Update/Delete any level of user in Cognos Controller. IBM X-Force ID: 186625.

    Published: 11 Nov 2020
    5.3
    Medium

    CVE-2020-7767

    Last Modified: 21 Nov 2024

    All versions of package express-validators are vulnerable to Regular Expression Denial of Service (ReDoS) when validating specifically-crafted invalid urls.

    Published: 11 Nov 2020
    7.2
    High

    CVE-2020-7329

    Last Modified: 21 Nov 2024

    Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.

    Published: 11 Nov 2020
    7.2
    High

    CVE-2020-7328

    Last Modified: 21 Nov 2024

    External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.

    Published: 11 Nov 2020
    5.4
    Medium

    CVE-2020-1325

    Last Modified: 21 Nov 2024

    Azure DevOps Server and Team Foundation Services Spoofing Vulnerability

    Published: 11 Nov 2020
    5.5
    Medium

    CVE-2020-1599

    Last Modified: 21 Nov 2024

    Windows Spoofing Vulnerability

    Published: 11 Nov 2020
    5.5
    Medium

    CVE-2020-17113

    Last Modified: 21 Nov 2024

    Windows Camera Codec Information Disclosure Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17110

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17107

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17108

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17109

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17105

    Last Modified: 21 Nov 2024

    AV1 Video Extension Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17106

    Last Modified: 21 Nov 2024

    HEVC Video Extensions Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    5.5
    Medium

    CVE-2020-17102

    Last Modified: 21 Nov 2024

    WebP Image Extensions Information Disclosure Vulnerability

    Published: 11 Nov 2020
    7.8
    High

    CVE-2020-17104

    Last Modified: 21 Nov 2024

    Visual Studio Code JSHint Extension Remote Code Execution Vulnerability

    Published: 11 Nov 2020
    5.5
    Medium

    CVE-2020-17100

    Last Modified: 21 Nov 2024

    Visual Studio Tampering Vulnerability

    Published: 11 Nov 2020