CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-14240

    Last Modified: 21 Nov 2024

    HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

    Published: 5 Nov 2020
    8.8
    High

    CVE-2020-25398

    Last Modified: 21 Nov 2024

    CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

    Published: 5 Nov 2020
    7.8
    High

    CVE-2020-25399

    Last Modified: 21 Nov 2024

    Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

    Published: 5 Nov 2020
    4.3
    Medium

    CVE-2020-26506

    Last Modified: 21 Nov 2024

    An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users. The accessed files were not visible by the low privileged users in the web GUI.

    Published: 5 Nov 2020
    7.5
    High

    CVE-2020-27688

    Last Modified: 21 Nov 2024

    RVToolsPasswordEncryption.exe in RVTools 4.0.6 allows users to encrypt passwords to be used in the configuration files. This encryption used a static IV and key, and thus using the Decrypt() method from VISKD.cs from the RVTools.exe executable allows for decrypting the encrypted passwords. The accounts used in the configuration files have access to vSphere instances.

    Published: 5 Nov 2020
    8.8
    High

    CVE-2020-28115

    Last Modified: 21 Nov 2024

    SQL Injection vulnerability in "Documents component" found in AudimexEE version 14.1.0 allows an attacker to execute arbitrary SQL commands via the object_path parameter.

    Published: 5 Nov 2020
    9.8
    Critical

    CVE-2020-27955

    Last Modified: 21 Nov 2024

    Git LFS 2.12.0 allows Remote Code Execution.

    Published: 5 Nov 2020
    5.4
    Medium

    CVE-2020-28047

    Last Modified: 21 Nov 2024

    AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.

    Published: 5 Nov 2020
    8.8
    High

    CVE-2020-15950

    Last Modified: 21 Nov 2024

    Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

    Published: 5 Nov 2020
    7.5
    High

    CVE-2020-15949

    Last Modified: 21 Nov 2024

    Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover.

    Published: 5 Nov 2020
    6.1
    Medium

    CVE-2020-15951

    Last Modified: 21 Nov 2024

    Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.

    Published: 5 Nov 2020
    9
    Critical

    CVE-2020-15952

    Last Modified: 21 Nov 2024

    Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.

    Published: 5 Nov 2020
    7.8
    High

    CVE-2020-27402

    Last Modified: 21 Nov 2024

    The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.

    Published: 5 Nov 2020
    8.8
    High

    CVE-2020-24849

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317.

    Published: 5 Nov 2020
    7.5
    High

    CVE-2020-7763

    Last Modified: 21 Nov 2024

    This affects the package phantom-html-to-pdf before 0.6.1.

    Published: 5 Nov 2020
    6.5
    Medium

    CVE-2020-7762

    Last Modified: 21 Nov 2024

    This affects the package jsreport-chrome-pdf before 1.10.0.

    Published: 5 Nov 2020
    5.3
    Medium

    CVE-2020-7761

    Last Modified: 21 Nov 2024

    This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails.

    Published: 5 Nov 2020
    7.8
    High

    CVE-2020-25669

    Last Modified: 21 Nov 2024

    A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkbd_disconnect, there is still an alias in sunkbd_reinit causing Use After Free.

    Published: 5 Nov 2020
    8.8
    High

    CVE-2020-27387

    Last Modified: 21 Nov 2024

    An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on the server) with the PHP extension, and finally executing the PHP file via an HTTP GET request to /storage/<php_file_name>. NOTE: the vendor has patched this while leaving the version number at 1.0.0-beta.

    Published: 5 Nov 2020
    7
    High

    CVE-2020-35514

    Last Modified: 21 Nov 2024

    An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects versions before openshift4/ose-machine-config-operator v4.7.0-202105111858.p0.

    Published: 5 Nov 2020
    9.8
    Critical

    CVE-2020-17510

    Last Modified: 21 Nov 2024

    Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.

    Published: 5 Nov 2020
    3.5
    Low

    CVE-2020-25688

    Last Modified: 21 Nov 2024

    A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.

    Published: 5 Nov 2020
    7.1
    High

    CVE-2021-20267

    Last Modified: 21 Nov 2024

    A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.

    Published: 5 Nov 2020
    7.5
    High

    CVE-2020-25201

    Last Modified: 21 Nov 2024

    HashiCorp Consul Enterprise version 1.7.0 up to 1.8.4 includes a namespace replication bug which can be triggered to cause denial of service via infinite Raft writes. Fixed in 1.7.9 and 1.8.5.

    Published: 4 Nov 2020
    8
    High

    CVE-2020-26207

    Last Modified: 21 Nov 2024

    DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

    Published: 4 Nov 2020
    8.8
    High

    CVE-2020-27692

    Last Modified: 21 Nov 2024

    The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains multiple CSRF vulnerabilities within its web management portal. Attackers can, for example, use this to update the TR-069 configuration server settings (responsible for managing devices remotely). This makes it possible to remotely reboot the device or upload malicious firmware.

    Published: 4 Nov 2020
    6.1
    Medium

    CVE-2020-27691

    Last Modified: 21 Nov 2024

    The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 allows XSS via URLBlocking Settings, SNMP Settings, and System Log Settings.

    Published: 4 Nov 2020
    5.5
    Medium

    CVE-2020-27690

    Last Modified: 21 Nov 2024

    The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains a buffer overflow within its web management portal. When a POST request is sent to /boaform/admin/formDOMAINBLK with a large blkDomain value, the Boa server crashes.

    Published: 4 Nov 2020
    9.8
    Critical

    CVE-2020-27689

    Last Modified: 21 Nov 2024

    The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and execute commands on the device, as well as upgrade the firmware image to a malicious version.

    Published: 4 Nov 2020
    5.4
    Medium

    CVE-2019-7356

    Last Modified: 21 Nov 2024

    Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.

    Published: 4 Nov 2020
    9.8
    Critical

    CVE-2020-7128

    Last Modified: 21 Nov 2024

    A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 4 Nov 2020
    7.2
    High

    CVE-2020-7129

    Last Modified: 21 Nov 2024

    A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 4 Nov 2020
    9.8
    Critical

    CVE-2020-22274

    Last Modified: 21 Nov 2024

    JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.

    Published: 4 Nov 2020
    6.5
    Medium

    CVE-2020-22273

    Last Modified: 21 Nov 2024

    Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)

    Published: 4 Nov 2020
    8.8
    High

    CVE-2020-22275

    Last Modified: 21 Nov 2024

    Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.

    Published: 4 Nov 2020
    8
    High

    CVE-2020-22277

    Last Modified: 21 Nov 2024

    Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.

    Published: 4 Nov 2020
    9.8
    Critical

    CVE-2020-22276

    Last Modified: 21 Nov 2024

    WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

    Published: 4 Nov 2020
    8.8
    High

    CVE-2020-22278

    Last Modified: 21 Nov 2024

    phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.

    Published: 4 Nov 2020
    9.8
    Critical

    CVE-2020-26167

    Last Modified: 30 May 2025

    In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.

    Published: 4 Nov 2020
    6.5
    Medium

    CVE-2020-2318

    Last Modified: 21 Nov 2024

    Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 4 Nov 2020
    6.5
    Medium

    CVE-2020-2319

    Last Modified: 21 Nov 2024

    Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 4 Nov 2020
    5.4
    Medium

    CVE-2020-2316

    Last Modified: 21 Nov 2024

    Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 4 Nov 2020
    5.4
    Medium

    CVE-2020-2317

    Last Modified: 21 Nov 2024

    Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step.

    Published: 4 Nov 2020
    5.5
    Medium

    CVE-2020-2314

    Last Modified: 21 Nov 2024

    Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 4 Nov 2020
    6.5
    Medium

    CVE-2020-2315

    Last Modified: 21 Nov 2024

    Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 4 Nov 2020
    6.5
    Medium

    CVE-2020-2312

    Last Modified: 21 Nov 2024

    Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.

    Published: 4 Nov 2020
    4.3
    Medium

    CVE-2020-2313

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 4 Nov 2020
    4.3
    Medium

    CVE-2020-2311

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.

    Published: 4 Nov 2020
    4.3
    Medium

    CVE-2020-2310

    Last Modified: 21 Nov 2024

    Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 4 Nov 2020
    4.3
    Medium

    CVE-2020-2303

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.

    Published: 4 Nov 2020