CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-28045

    Last Modified: 21 Nov 2024

    An unsigned-library issue was discovered in ProlinOS through 2.4.161.8859R. This OS requires installed applications and all system binaries to be signed either by the manufacturer or by the Point Of Sale application developer and distributor. The signature is a 2048-byte RSA signature verified in the kernel prior to ELF execution. Shared libraries, however, do not need to be signed, and they are not verified. An attacker may execute a custom binary by compiling it as a shared object and loading it via LD_PRELOAD.

    Published: 1 Nov 2020
    7.8
    High

    CVE-2020-28046

    Last Modified: 21 Nov 2024

    An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate to root privileges by exploiting the setuid installation of the xtables-multi binary and leveraging the ip6tables --modprobe switch.

    Published: 1 Nov 2020
    8.8
    High

    CVE-2020-25849

    Last Modified: 21 Nov 2024

    MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.

    Published: 1 Nov 2020
    7.5
    High

    CVE-2020-28043

    Last Modified: 21 Nov 2024

    MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

    Published: 1 Nov 2020
    5.3
    Medium

    CVE-2020-28042

    Last Modified: 21 Nov 2024

    ServiceStack before 5.9.2 mishandles JWT signature verification unless an application has a custom ValidateToken function that establishes a valid minimum length for a signature.

    Published: 1 Nov 2020
    6.5
    Medium

    CVE-2020-28041

    Last Modified: 21 Nov 2024

    The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP services on a victim's intranet machine, if the victim visits an attacker-controlled web site with a modern browser, aka NAT Slipstreaming. This occurs because the ALG takes action based on an IP packet with an initial REGISTER substring in the TCP data, and the correct intranet IP address in the subsequent Via header, without properly considering that connection progress and fragmentation affect the meaning of the packet data.

    Published: 1 Nov 2020
    7.8
    High

    CVE-2020-25671

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.

    Published: 1 Nov 2020
    5.5
    Medium

    CVE-2020-25673

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.

    Published: 1 Nov 2020
    7.5
    High

    CVE-2020-25672

    Last Modified: 21 Nov 2024

    A memory leak vulnerability was found in Linux kernel in llcp_sock_connect

    Published: 1 Nov 2020
    7.8
    High

    CVE-2020-25670

    Last Modified: 21 Nov 2024

    A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.

    Published: 1 Nov 2020
    7.9
    High

    CVE-2020-5425

    Last Modified: 21 Nov 2024

    Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same username, from two different identity providers, one can acquire the token of the other and thus operate with their permissions. Note: Foundation may be vulnerable only if: 1) The system zone is set up to use a SAML identity provider 2) There are internal users that have the same username as users in the external SAML provider 3) Those duplicate-named users have the scope to access the SSO operator dashboard 4) The vulnerability doesn't appear with LDAP because of chained authentication.

    Published: 31 Oct 2020
    5.4
    Medium

    CVE-2020-27359

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.

    Published: 31 Oct 2020
    4.3
    Medium

    CVE-2020-27358

    Last Modified: 21 Nov 2024

    An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request to the endpoint Messenger/messenger_download_csv.php?title=Hey&thread_id={THREAD_ID}.

    Published: 31 Oct 2020
    7.8
    High

    CVE-2020-27992

    Last Modified: 21 Nov 2024

    Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.

    Published: 31 Oct 2020
    4
    Medium

    CVE-2020-15703

    Last Modified: 21 Nov 2024

    There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path to a writable directory, which lets aptd read a file as root. Having a symlink in place results in an error message if the file exists, and no error otherwise. This way an unprivileged user can check for the existence of any files on the system as root.

    Published: 31 Oct 2020
    9.8
    Critical

    CVE-2020-28032

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.

    Published: 31 Oct 2020
    7.5
    High

    CVE-2020-28033

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.

    Published: 31 Oct 2020
    6.1
    Medium

    CVE-2020-28034

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 allows XSS associated with global variables.

    Published: 31 Oct 2020
    9.8
    Critical

    CVE-2020-28036

    Last Modified: 21 Nov 2024

    wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

    Published: 31 Oct 2020
    9.8
    Critical

    CVE-2020-28037

    Last Modified: 21 Nov 2024

    is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).

    Published: 31 Oct 2020
    6.1
    Medium

    CVE-2020-28038

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 allows stored XSS via post slugs.

    Published: 31 Oct 2020
    4.3
    Medium

    CVE-2020-28040

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

    Published: 31 Oct 2020
    9.1
    Critical

    CVE-2020-28039

    Last Modified: 21 Nov 2024

    is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

    Published: 31 Oct 2020
    9.8
    Critical

    CVE-2020-28035

    Last Modified: 21 Nov 2024

    WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

    Published: 31 Oct 2020
    4.3
    Medium

    CVE-2020-28031

    Last Modified: 21 Nov 2024

    eramba through c2.8.1 allows HTTP Host header injection with (for example) resultant wkhtml2pdf PDF printing by authenticated users.

    Published: 30 Oct 2020
    7.8
    High

    CVE-2020-5991

    Last Modified: 21 Nov 2024

    NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.

    Published: 30 Oct 2020
    7.3
    High

    CVE-2020-15273

    Last Modified: 21 Nov 2024

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in the account that can access the file upload function category list, subsite setting list, widget area edit, and feed list on the management screen. The issue was introduced in version 4.0.0. It is fixed in version 4.4.1.

    Published: 30 Oct 2020
    7.7
    High

    CVE-2020-15276

    Last Modified: 21 Nov 2024

    baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-8183

    Last Modified: 21 Nov 2024

    A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

    Published: 30 Oct 2020
    2.2
    Low

    CVE-2020-8173

    Last Modified: 21 Nov 2024

    A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.

    Published: 30 Oct 2020
    6.8
    Medium

    CVE-2020-8236

    Last Modified: 21 Nov 2024

    A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

    Published: 30 Oct 2020
    7.2
    High

    CVE-2020-15277

    Last Modified: 21 Nov 2024

    baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.

    Published: 30 Oct 2020
    9.8
    Critical

    CVE-2020-7373

    Last Modified: 21 Nov 2024

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.

    Published: 30 Oct 2020
    5.4
    Medium

    CVE-2020-15914

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.

    Published: 30 Oct 2020
    7.8
    High

    CVE-2020-27708

    Last Modified: 21 Nov 2024

    A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for high privileged users or system Administrators.

    Published: 30 Oct 2020
    6.5
    Medium

    CVE-2020-6014

    Last Modified: 21 Nov 2024

    Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

    Published: 30 Oct 2020
    7.8
    High

    CVE-2020-4588

    Last Modified: 21 Nov 2024

    IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-4584

    Last Modified: 21 Nov 2024

    IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 184574.

    Published: 30 Oct 2020
    6.5
    Medium

    CVE-2020-7759

    Last Modified: 21 Nov 2024

    The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the following request: http://vulnerable.pimcore.example/admin/classificationstore/relations?relationIds=[{"keyId"%3a"''","groupId"%3a"'asd'))+or+1%3d1+union+(select+1,2,3,4,5,6,name,8,password,'',11,12,'',14+from+users)+--+"}]

    Published: 30 Oct 2020
    6.5
    Medium

    CVE-2020-5657

    Last Modified: 21 Nov 2024

    Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-5658

    Last Modified: 21 Nov 2024

    Resource Management Errors vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-5655

    Last Modified: 21 Nov 2024

    NULL pointer dereferences vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.

    Published: 30 Oct 2020
    9.8
    Critical

    CVE-2020-5656

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

    Published: 30 Oct 2020
    9.8
    Critical

    CVE-2020-5653

    Last Modified: 21 Nov 2024

    Buffer overflow vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-5654

    Last Modified: 21 Nov 2024

    Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R series (RJ71EIP91 EtherNet/IP Network Interface Module First 2 digits of serial number are '02' or before, RJ71PN92 PROFINET IO Controller Module First 2 digits of serial number are '01' or before, RD81DL96 High Speed Data Logger Module First 2 digits of serial number are '08' or before, RD81MES96N MES Interface Module First 2 digits of serial number are '04' or before, and RD81OPC96 OPC UA Server Module First 2 digits of serial number are '04' or before) allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-5652

    Last Modified: 21 Nov 2024

    Uncontrolled resource consumption vulnerability in Ethernet Port on MELSEC iQ-R, Q and L series CPU modules (R 00/01/02 CPU firmware versions '20' and earlier, R 04/08/16/32/120 (EN) CPU firmware versions '52' and earlier, R 08/16/32/120 SFCPU firmware versions '22' and earlier, R 08/16/32/120 PCPU all versions, R 08/16/32/120 PSFCPU all versions, R 16/32/64 MTCPU all versions, Q03 UDECPU, Q 04/06/10/13/20/26/50/100 UDEHCPU serial number '22081' and earlier , Q 03/04/06/13/26 UDVCPU serial number '22031' and earlier, Q 04/06/13/26 UDPVCPU serial number '22031' and earlier, Q 172/173 DCPU all versions, Q 172/173 DSCPU all versions, Q 170 MCPU all versions, Q 170 MSCPU all versions, L 02/06/26 CPU (-P) and L 26 CPU - (P) BT all versions) allows a remote unauthenticated attacker to stop the Ethernet communication functions of the products via a specially crafted packet, which may lead to a denial of service (DoS) condition .

    Published: 30 Oct 2020
    5.3
    Medium

    CVE-2020-28002

    Last Modified: 21 Nov 2024

    In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.

    Published: 30 Oct 2020
    8.8
    High

    CVE-2020-27347

    Last Modified: 21 Nov 2024

    In tmux before version 3.1c the function input_csi_dispatch_sgr_colon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.

    Published: 30 Oct 2020
    7.5
    High

    CVE-2020-28030

    Last Modified: 21 Nov 2024

    In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

    Published: 30 Oct 2020
    7
    High

    CVE-2020-25668

    Last Modified: 21 Nov 2024

    A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

    Published: 30 Oct 2020