CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-11483

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-coded credentials, which may lead to elevation of privileges or information disclosure.

    Published: 29 Oct 2020
    4.9
    Medium

    CVE-2020-11484

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of the BMC/IPMI user password, which may lead to information disclosure.

    Published: 29 Oct 2020
    8.8
    High

    CVE-2020-11485

    Last Modified: 21 Nov 2024

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC firmware in which the web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request, which can lead to information disclosure or code execution.

    Published: 29 Oct 2020
    6.5
    Medium

    CVE-2020-14383

    Last Modified: 21 Nov 2024

    A flaw was found in samba's DNS server. An authenticated user could use this flaw to the RPC server to crash. This RPC server, which also serves protocols other than dnsserver, will be restarted after a short delay, but it is easy for an authenticated non administrative attacker to crash it again as soon as it returns. The Samba DNS server itself will continue to operate, but many RPC services will not.

    Published: 29 Oct 2020
    5.4
    Medium

    CVE-2020-25680

    Last Modified: 21 Nov 2024

    A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is to data integrity.

    Published: 29 Oct 2020
    4.3
    Medium

    CVE-2020-14318

    Last Modified: 21 Nov 2024

    A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-7793

    Last Modified: 21 Nov 2024

    The package ua-parser-js before 0.7.23 are vulnerable to Regular Expression Denial of Service (ReDoS) in multiple regexes (see linked commit for more info).

    Published: 29 Oct 2020
    5.5
    Medium

    CVE-2020-14323

    Last Modified: 21 Nov 2024

    A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.

    Published: 29 Oct 2020
    5.9
    Medium

    CVE-2020-28168

    Last Modified: 21 Nov 2024

    Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

    Published: 29 Oct 2020
    7.5
    High

    CVE-2020-27986

    Last Modified: 21 Nov 2024

    SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

    Published: 28 Oct 2020
    —
    Unknown

    CVE-2020-27981

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Oct 2020
    2.6
    Low

    CVE-2020-25374

    Last Modified: 21 Nov 2024

    CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-24707

    Last Modified: 21 Nov 2024

    Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-24713

    Last Modified: 21 Nov 2024

    Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.

    Published: 28 Oct 2020
    6.5
    Medium

    CVE-2020-24711

    Last Modified: 21 Nov 2024

    The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

    Published: 28 Oct 2020
    5.3
    Medium

    CVE-2020-24710

    Last Modified: 21 Nov 2024

    Gophish before 0.11.0 allows SSRF attacks.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-24712

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-24709

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-24708

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-24990

    Last Modified: 21 Nov 2024

    An issue was discovered in QSC Q-SYS Core Manager 8.2.1. By utilizing the TFTP service running on UDP port 69, a remote attacker can perform a directory traversal and obtain operating system files via a TFTP GET request, as demonstrated by reading /etc/passwd or /proc/version.

    Published: 28 Oct 2020
    5.5
    Medium

    CVE-2020-25204

    Last Modified: 21 Nov 2024

    The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However, the application does not enforce any authorization schema on the broadcast receiver, allowing any application to send fully customizable in-game push notifications.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-27980

    Last Modified: 21 Nov 2024

    Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-27739

    Last Modified: 21 Nov 2024

    A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

    Published: 28 Oct 2020
    6.5
    Medium

    CVE-2020-27742

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails via the msg_confirm_move template. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

    Published: 28 Oct 2020
    6.1
    Medium

    CVE-2020-27741

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

    Published: 28 Oct 2020
    5.3
    Medium

    CVE-2020-27740

    Last Modified: 21 Nov 2024

    Citadel WebCit through 926 allows unauthenticated remote attackers to enumerate valid users within the platform. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.

    Published: 28 Oct 2020
    6.1
    Medium

    CVE-2018-19953

    Last Modified: 3 Nov 2025

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2018-19949

    Last Modified: 3 Nov 2025

    If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

    Published: 28 Oct 2020
    8
    High

    CVE-2018-19943

    Last Modified: 3 Nov 2025

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-25966

    Last Modified: 21 Nov 2024

    Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-16259

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user.

    Published: 28 Oct 2020
    7.1
    High

    CVE-2020-16258

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-16260

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.

    Published: 28 Oct 2020
    9.1
    Critical

    CVE-2020-16263

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins.

    Published: 28 Oct 2020
    7.8
    High

    CVE-2020-16262

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

    Published: 28 Oct 2020
    6.8
    Medium

    CVE-2020-16261

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access.

    Published: 28 Oct 2020
    8.8
    High

    CVE-2020-16256

    Last Modified: 21 Nov 2024

    The API on Winston 1.5.4 devices is vulnerable to CSRF.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-16257

    Last Modified: 21 Nov 2024

    Winston 1.5.4 devices are vulnerable to command injection via the API.

    Published: 28 Oct 2020
    7.7
    High

    CVE-2020-15278

    Last Modified: 21 Nov 2024

    Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a high privilege level within the guild to bypass hierarchy checks when the application is in a specific condition that is beyond that user's control. By abusing this exploit, it is possible to perform destructive actions within the guild the user has high privileges in. This exploit has been fixed in version 3.4.1. As a workaround, unloading the Mod module with unload mod or, disabling the massban command with command disable global massban can render this exploit not accessible. We still highly recommend updating to 3.4.1 to completely patch this issue.

    Published: 28 Oct 2020
    6.5
    Medium

    CVE-2020-4782

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-4767

    Last Modified: 21 Nov 2024

    IBM Sterling Connect Direct for Microsoft Windows 4.7, 4.8, 6.0, and 6.1 could allow a remote attacker to cause a denial of service, caused by a buffer over-read. Bysending a specially crafted request, the attacker could cause the application to crash. IBM X-Force ID: 188906.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-27978

    Last Modified: 21 Nov 2024

    Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container session.

    Published: 28 Oct 2020
    6.1
    Medium

    CVE-2020-27974

    Last Modified: 21 Nov 2024

    NeoPost Mail Accounting Software Pro 5.0.6 allows php/Commun/FUS_SCM_BlockStart.php?code= XSS.

    Published: 28 Oct 2020
    8.8
    High

    CVE-2020-27975

    Last Modified: 21 Nov 2024

    osCommerce Phoenix CE before 1.0.5.4 allows admin/define_language.php CSRF.

    Published: 28 Oct 2020
    9.8
    Critical

    CVE-2020-27976

    Last Modified: 21 Nov 2024

    osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.

    Published: 28 Oct 2020
    7.5
    High

    CVE-2020-22552

    Last Modified: 21 Nov 2024

    The Snap7 server component in version 1.4.1, when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function, the Snap7 server will be crashed.

    Published: 28 Oct 2020
    5.4
    Medium

    CVE-2020-8263

    Last Modified: 21 Nov 2024

    A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.

    Published: 28 Oct 2020
    6.1
    Medium

    CVE-2020-8262

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

    Published: 28 Oct 2020
    4.3
    Medium

    CVE-2020-8261

    Last Modified: 21 Nov 2024

    A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.

    Published: 28 Oct 2020
    7.2
    High

    CVE-2020-8260

    Last Modified: 30 Oct 2025

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

    Published: 28 Oct 2020