CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2020-25689

    Last Modified: 21 Nov 2024

    A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 30 Oct 2020
    6.4
    Medium

    CVE-2020-27014

    Last Modified: 21 Nov 2024

    Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

    Published: 29 Oct 2020
    4.4
    Medium

    CVE-2020-27015

    Last Modified: 21 Nov 2024

    Trend Micro Antivirus for Mac 2020 (Consumer) contains an Error Message Information Disclosure vulnerability that if exploited, could allow kernel pointers and debug messages to leak to userland. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

    Published: 29 Oct 2020
    6.1
    Medium

    CVE-2020-27885

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability on WSO2 API Manager 3.1.0. By exploiting a Cross-site scripting vulnerability the attacker can hijack a logged-in user’s session by stealing cookies which means that a malicious hacker can change the logged-in user’s password and invalidate the session of the victim while the hacker maintains access.

    Published: 29 Oct 2020
    7.6
    High

    CVE-2020-26205

    Last Modified: 21 Nov 2024

    Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-25646

    Last Modified: 21 Nov 2024

    A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private key in logs. This directly impacts confidentiality

    Published: 29 Oct 2020
    8.8
    High

    CVE-2020-27887

    Last Modified: 21 Nov 2024

    An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the nmap_binary parameter to lilac/autodiscovery.php.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-27886

    Last Modified: 21 Nov 2024

    An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).

    Published: 29 Oct 2020
    6.8
    Medium

    CVE-2020-27747

    Last Modified: 21 Nov 2024

    An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker retrieves all passwords from another systems, available for affected account.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-27998

    Last Modified: 21 Nov 2024

    An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.

    Published: 29 Oct 2020
    8.8
    High

    CVE-2020-27996

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-27995

    Last Modified: 21 Nov 2024

    SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-27744

    Last Modified: 21 Nov 2024

    An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-25780

    Last Modified: 21 Nov 2024

    In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.

    Published: 29 Oct 2020
    4.3
    Medium

    CVE-2020-4864

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 could allow an attacker on the internal net work to provide the server with a spoofed source IP address. IBM X-Force ID: 190567.

    Published: 29 Oct 2020
    7.8
    High

    CVE-2020-4724

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

    Published: 29 Oct 2020
    7.8
    High

    CVE-2020-4723

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187873.

    Published: 29 Oct 2020
    7.8
    High

    CVE-2020-4722

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187870.

    Published: 29 Oct 2020
    7.8
    High

    CVE-2020-4721

    Last Modified: 21 Nov 2024

    IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 187868.

    Published: 29 Oct 2020
    5.3
    Medium

    CVE-2019-4563

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.

    Published: 29 Oct 2020
    5.3
    Medium

    CVE-2019-4547

    Last Modified: 21 Nov 2024

    IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-5936

    Last Modified: 21 Nov 2024

    On BIG-IP LTM 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.1, the Traffic Management Microkernel (TMM) process may consume excessive resources when processing SSL traffic and client authentication are enabled on the client SSL profile.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-5934

    Last Modified: 21 Nov 2024

    On BIG-IP APM 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when multiple HTTP requests from the same client to configured SAML Single Logout (SLO) URL are passing through a TCP Keep-Alive connection, traffic to TMM can be disrupted.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-5931

    Last Modified: 21 Nov 2024

    On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with a OneConnect profile may incorrectly handle WebSockets related HTTP response headers, causing TMM to restart.

    Published: 29 Oct 2020
    4.8
    Medium

    CVE-2020-5932

    Last Modified: 21 Nov 2024

    On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privileges can specify a response page with any content, including JavaScript code that will be executed when preview is opened.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-5933

    Last Modified: 21 Nov 2024

    On versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, when a BIG-IP system that has a virtual server configured with an HTTP compression profile processes compressed HTTP message payloads that require deflation, a Slowloris-style attack can trigger an out-of-memory condition on the BIG-IP system.

    Published: 29 Oct 2020
    5.9
    Medium

    CVE-2020-5935

    Last Modified: 21 Nov 2024

    On BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link Controller, PEM) versions 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, and 13.1.0-13.1.3.3, when handling MQTT traffic through a BIG-IP virtual server associated with an MQTT profile and an iRule performing manipulations on that traffic, TMM may produce a core file.

    Published: 29 Oct 2020
    5.3
    Medium

    CVE-2020-27993

    Last Modified: 21 Nov 2024

    Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.

    Published: 29 Oct 2020
    7
    High

    CVE-2020-7384

    Last Modified: 21 Nov 2024

    Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.

    Published: 29 Oct 2020
    6.1
    Medium

    CVE-2020-21266

    Last Modified: 21 Nov 2024

    Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-5937

    Last Modified: 21 Nov 2024

    On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4 (L4) behavioral denial-of-service (DoS) traffic.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-5938

    Last Modified: 21 Nov 2024

    On BIG-IP 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when negotiating IPSec tunnels with configured, authenticated peers, the peer may negotiate a different key length than the BIG-IP configuration would otherwise allow.

    Published: 29 Oct 2020
    5.4
    Medium

    CVE-2020-25516

    Last Modified: 21 Nov 2024

    WSO2 Enterprise Integrator 6.6.0 or earlier contains a stored cross-site scripting (XSS) vulnerability in BPMN explorer tasks.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-27656

    Last Modified: 14 Jan 2025

    Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.

    Published: 29 Oct 2020
    8.3
    High

    CVE-2020-27652

    Last Modified: 14 Jan 2025

    Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.

    Published: 29 Oct 2020
    5.8
    Medium

    CVE-2020-27650

    Last Modified: 14 Jan 2025

    Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

    Published: 29 Oct 2020
    8.3
    High

    CVE-2020-27648

    Last Modified: 14 Jan 2025

    Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Oct 2020
    7.1
    High

    CVE-2020-27658

    Last Modified: 21 Nov 2024

    Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-27657

    Last Modified: 21 Nov 2024

    Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-27655

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via inbound QuickConnect traffic.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-27654

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.

    Published: 29 Oct 2020
    8.3
    High

    CVE-2020-27653

    Last Modified: 14 Jan 2025

    Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.

    Published: 29 Oct 2020
    5.8
    Medium

    CVE-2020-27651

    Last Modified: 21 Nov 2024

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

    Published: 29 Oct 2020
    8.3
    High

    CVE-2020-27649

    Last Modified: 21 Nov 2024

    Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-11615

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-11616

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong, which may lead to information disclosure.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-11489

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.

    Published: 29 Oct 2020
    6.7
    Medium

    CVE-2020-11488

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.

    Published: 29 Oct 2020
    9.8
    Critical

    CVE-2020-11486

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-11487

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.

    Published: 29 Oct 2020