CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-7127

    Last Modified: 21 Nov 2024

    A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    5.8
    Medium

    CVE-2020-7126

    Last Modified: 21 Nov 2024

    A remote server-side request forgery (ssrf) vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    8.8
    High

    CVE-2020-7125

    Last Modified: 21 Nov 2024

    A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    9.8
    Critical

    CVE-2020-7124

    Last Modified: 21 Nov 2024

    A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    7.2
    High

    CVE-2020-24632

    Last Modified: 21 Nov 2024

    A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    7.2
    High

    CVE-2020-24631

    Last Modified: 21 Nov 2024

    A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

    Published: 26 Oct 2020
    7.5
    High

    CVE-2020-15897

    Last Modified: 21 Nov 2024

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.

    Published: 26 Oct 2020
    9.8
    Critical

    CVE-2020-7197

    Last Modified: 21 Nov 2024

    SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* Upgrade to HPE 3PAR StoreServ Management Console 3.7.1.1 or later.

    Published: 26 Oct 2020
    6.5
    Medium

    CVE-2020-7196

    Last Modified: 21 Nov 2024

    The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

    Published: 26 Oct 2020
    7.5
    High

    CVE-2020-13100

    Last Modified: 21 Nov 2024

    Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.

    Published: 26 Oct 2020
    6.1
    Medium

    CVE-2020-25470

    Last Modified: 21 Nov 2024

    AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

    Published: 26 Oct 2020
    5.3
    Medium

    CVE-2021-3470

    Last Modified: 21 Nov 2024

    A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

    Published: 26 Oct 2020
    6
    Medium

    CVE-2020-7751

    Last Modified: 21 Nov 2024

    pathval before version 1.1.1 is vulnerable to prototype pollution.

    Published: 25 Oct 2020
    5.9
    Medium

    CVE-2020-25659

    Last Modified: 21 Nov 2024

    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

    Published: 25 Oct 2020
    7.3
    High

    CVE-2020-28458

    Last Modified: 21 Nov 2024

    All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

    Published: 25 Oct 2020
    7.3
    High

    CVE-2020-7774

    Last Modified: 21 Nov 2024

    The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

    Published: 25 Oct 2020
    9.8
    Critical

    CVE-2020-27678

    Last Modified: 21 Nov 2024

    An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.

    Published: 23 Oct 2020
    5.4
    Medium

    CVE-2020-27388

    Last Modified: 21 Nov 2024

    Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-24848

    Last Modified: 21 Nov 2024

    FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.

    Published: 23 Oct 2020
    4.3
    Medium

    CVE-2020-24847

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticated attacker can change the newSSID and hostapd_wpa_passphrase.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-5990

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege escalation, code execution, denial of service or information disclosure.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-5978

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder is created by nvcontainer.exe under normal user login with LOCAL_SYSTEM privileges which may lead to a denial of service or escalation of privileges.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-5977

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published: 23 Oct 2020
    9.8
    Critical

    CVE-2020-25483

    Last Modified: 21 Nov 2024

    An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

    Published: 23 Oct 2020
    9.8
    Critical

    CVE-2020-25466

    Last Modified: 21 Nov 2024

    A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

    Published: 23 Oct 2020
    6.5
    Medium

    CVE-2020-3998

    Last Modified: 21 Nov 2024

    VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.

    Published: 23 Oct 2020
    5.4
    Medium

    CVE-2020-3997

    Last Modified: 21 Nov 2024

    VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.

    Published: 23 Oct 2020
    8.8
    High

    CVE-2020-26561

    Last Modified: 21 Nov 2024

    Belkin LINKSYS WRT160NL 1.0.04.002_US_20130619 devices have a stack-based buffer overflow vulnerability because of sprintf in create_dir in mini_httpd. Successful exploitation leads to arbitrary code execution. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 23 Oct 2020
    6.8
    Medium

    CVE-2019-14715

    Last Modified: 21 Nov 2024

    Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write operation.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-26887

    Last Modified: 21 Nov 2024

    FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.

    Published: 23 Oct 2020
    4.8
    Medium

    CVE-2020-15004

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.

    Published: 23 Oct 2020
    4.3
    Medium

    CVE-2020-15003

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).

    Published: 23 Oct 2020
    5
    Medium

    CVE-2020-15002

    Last Modified: 21 Nov 2024

    OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2020-9331

    Last Modified: 21 Nov 2024

    CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space.

    Published: 23 Oct 2020
    5.5
    Medium

    CVE-2020-9361

    Last Modified: 21 Nov 2024

    CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation.

    Published: 23 Oct 2020
    6.6
    Medium

    CVE-2019-14716

    Last Modified: 21 Nov 2024

    Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).

    Published: 23 Oct 2020
    7.8
    High

    CVE-2019-14717

    Last Modified: 21 Nov 2024

    Verifone Verix OS on VerixV Pinpad Payment Terminals with QT000530 have a Buffer Overflow via the Run system call.

    Published: 23 Oct 2020
    6.7
    Medium

    CVE-2019-14718

    Last Modified: 21 Nov 2024

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2019-14719

    Last Modified: 21 Nov 2024

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.

    Published: 23 Oct 2020
    5.5
    Medium

    CVE-2019-14713

    Last Modified: 21 Nov 2024

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.

    Published: 23 Oct 2020
    7.8
    High

    CVE-2019-14712

    Last Modified: 21 Nov 2024

    Verifone VerixV Pinpad Payment Terminals with QT000530 allow bypass of integrity and origin control for S1G file generation.

    Published: 23 Oct 2020
    7
    High

    CVE-2019-14711

    Last Modified: 21 Nov 2024

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have a race condition for RBAC bypass.

    Published: 23 Oct 2020
    5.4
    Medium

    CVE-2018-8062

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.

    Published: 23 Oct 2020
    —
    Unknown

    CVE-2018-21267

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Oct 2020
    —
    Unknown

    CVE-2018-21266

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 22 Oct 2020
    4.3
    Medium

    CVE-2020-15270

    Last Modified: 21 Nov 2024

    Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session tokens. The issue is not patched.

    Published: 22 Oct 2020
    8.8
    High

    CVE-2020-11853

    Last Modified: 21 Nov 2024

    Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.05, 11, 10.33, 10.32, 10.31, 10.30 6.) Hybrid Cloud Management affecting version 2020.05 7.) Service Management Automation affecting version 2020.5 and 2020.02. The vulnerability could allow to execute arbitrary code.

    Published: 22 Oct 2020
    5.3
    Medium

    CVE-2020-15680

    Last Modified: 21 Nov 2024

    If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

    Published: 22 Oct 2020
    7.5
    High

    CVE-2020-15681

    Last Modified: 21 Nov 2024

    When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 82.

    Published: 22 Oct 2020
    6.5
    Medium

    CVE-2020-15682

    Last Modified: 21 Nov 2024

    When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

    Published: 22 Oct 2020