CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-27163

    Last Modified: 21 Nov 2024

    phpRedisAdmin before 1.13.2 allows XSS via the login.php username parameter.

    Published: 16 Oct 2020
    7.8
    High

    CVE-2019-14584

    Last Modified: 21 Nov 2024

    Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-7754

    Last Modified: 21 Nov 2024

    This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.

    Published: 16 Oct 2020
    4.1
    Medium

    CVE-2020-25656

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

    Published: 16 Oct 2020
    7.5
    High

    CVE-2020-16947

    Last Modified: 23 Feb 2026

    <p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Outlook software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.</p> <p>Note that where severity is indicated as Critical in the Affected Products table, the Preview Pane is an attack vector.</p> <p>The security update addresses the vulnerability by correcting how Outlook handles objects in memory.</p>

    Published: 16 Oct 2020
    5.3
    Medium

    CVE-2020-14185

    Last Modified: 21 Nov 2024

    Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2019-17640

    Last Modified: 21 Nov 2024

    In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.

    Published: 15 Oct 2020
    4.3
    Medium

    CVE-2020-1777

    Last Modified: 21 Nov 2024

    Agent names that participates in a chat conversation are revealed in certain parts of the external interface as well as in chat transcriptions inside the tickets, when system is configured to mask real agent names. This issue affects OTRS; 7.0.21 and prior versions, 8.0.6 and prior versions.

    Published: 15 Oct 2020
    8.8
    High

    CVE-2020-7591

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administrative) actions on behalf of those users if the single sign-on feature ("Allow logon without password") is enabled.

    Published: 15 Oct 2020
    4.3
    Medium

    CVE-2020-15794

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Desigo Insight (All versions). Some error messages in the web application show the absolute path to the requested resource. This could allow an authenticated attacker to retrieve additional information about the host system.

    Published: 15 Oct 2020
    4.3
    Medium

    CVE-2020-15792

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based blind SQL injection attack.

    Published: 15 Oct 2020
    5.4
    Medium

    CVE-2020-15793

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Desigo Insight (All versions). The device does not properly set the X-Frame-Options HTTP Header which makes it vulnerable to Clickjacking attacks. This could allow an unauthenticated attacker to retrieve or modify data in the context of a legitimate user by tricking that user to click on a website controlled by the attacker.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2020-12504

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below has an active TFTP-Service.

    Published: 15 Oct 2020
    7.2
    High

    CVE-2020-12503

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to multiple authenticated command injections.

    Published: 15 Oct 2020
    8.8
    High

    CVE-2020-12502

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) and ICRL-M-8RJ45/4SFP-G-DIN, ICRL-M-16RJ45/4CP-G-DIN FW 1.2.3 and below is prone to unauthenticated device administration.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2020-12501

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) use undocumented accounts.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2020-12500

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES8508, ES8508F, ES8510, ES8510-XTE, ES9528/ES9528-XT (all versions) allows unauthenticated device administration.

    Published: 15 Oct 2020
    6.7
    Medium

    CVE-2020-25859

    Last Modified: 21 Nov 2024

    The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validating the input, while handling a SetGatewayUrl() request. A local attacker with shell access can pass shell metacharacters and run arbitrary commands. If QCMAP_CLI can be run via sudo or setuid, this also allows elevating privileges to root. This version of QCMAP is used in many kinds of networking devices, primarily mobile hotspots and LTE routers.

    Published: 15 Oct 2020
    7.5
    High

    CVE-2020-25858

    Last Modified: 21 Nov 2024

    The QCMAP_Web_CLIENT binary in the Qualcomm QCMAP software suite prior to versions released in October 2020 does not validate the return value of a strstr() or strchr() call in the Tokenizer() function. An attacker who invokes the web interface with a crafted URL can crash the process, causing denial of service. This version of QCMAP is used in many kinds of networking devices, primarily mobile hotspots and LTE routers.

    Published: 15 Oct 2020
    5.8
    Medium

    CVE-2020-11637

    Last Modified: 21 Nov 2024

    A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.

    Published: 15 Oct 2020
    —
    Unknown

    CVE-2019-12411

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Oct 2020
    —
    Unknown

    CVE-2020-13939

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Oct 2020
    4.3
    Medium

    CVE-2020-11646

    Last Modified: 21 Nov 2024

    A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log information reserved for other users.

    Published: 15 Oct 2020
    6.5
    Medium

    CVE-2020-11645

    Last Modified: 21 Nov 2024

    A denial of service vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to limit availability of GateManager instances.

    Published: 15 Oct 2020
    7.7
    High

    CVE-2020-11642

    Last Modified: 21 Nov 2024

    The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.

    Published: 15 Oct 2020
    7.7
    High

    CVE-2020-11641

    Last Modified: 21 Nov 2024

    A local file inclusion vulnerability in B&R SiteManager versions <9.2.620236042 allows authenticated users to read sensitive files from SiteManager instances.

    Published: 15 Oct 2020
    6.5
    Medium

    CVE-2020-11644

    Last Modified: 21 Nov 2024

    The information disclosure vulnerability present in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to generate fake audit log messages.

    Published: 15 Oct 2020
    6.5
    Medium

    CVE-2020-11643

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.

    Published: 15 Oct 2020
    5.5
    Medium

    CVE-2020-6106

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 15 Oct 2020
    7.8
    High

    CVE-2020-6105

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 15 Oct 2020
    5.5
    Medium

    CVE-2020-6104

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the get_dnode_of_data functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause information disclosure resulting in a information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 15 Oct 2020
    7.8
    High

    CVE-2020-6108

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 15 Oct 2020
    5.5
    Medium

    CVE-2020-6107

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2020-4499

    Last Modified: 21 Nov 2024

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.

    Published: 15 Oct 2020
    6.1
    Medium

    CVE-2019-4552

    Last Modified: 21 Nov 2024

    IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.

    Published: 15 Oct 2020
    4.7
    Medium

    CVE-2020-7744

    Last Modified: 21 Nov 2024

    This affects all versions of package com.mintegral.msdk:alphab. The Android SDK distributed by the company contains malicious functionality in this module that tracks: 1. Downloads from Google urls either within Google apps or via browser including file downloads, e-mail attachments and Google Docs links. 2. All apk downloads, either organic or not. Mintegral listens to download events in Android's download manager and detects if the downloaded file's url contains: a. google.com or comes from a Google app (the com.android.vending package) b. Ends with .apk for apk downloads In both cases, the module sends the captured data back to Mintegral's servers. Note that the malicious functionality keeps running even if the app is currently not in focus (running in the background).

    Published: 15 Oct 2020
    6
    Medium

    CVE-2020-7327

    Last Modified: 21 Nov 2024

    Improperly implemented security check in McAfee MVISION Endpoint Detection and Response Client (MVEDR) prior to 3.2.0 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MVEDR failing open rather than closed

    Published: 15 Oct 2020
    6
    Medium

    CVE-2020-7326

    Last Modified: 21 Nov 2024

    Improperly implemented security check in McAfee Active Response (MAR) prior to 2.4.4 may allow local administrators to execute malicious code via stopping a core Windows service leaving McAfee core trust component in an inconsistent state resulting in MAR failing open rather than closed

    Published: 15 Oct 2020
    7.7
    High

    CVE-2020-7334

    Last Modified: 21 Nov 2024

    Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.

    Published: 15 Oct 2020
    9.8
    Critical

    CVE-2020-27156

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.5 did not perform adequate authorization checks. This vulnerability could allow for remote code execution by an unauthenticated user.

    Published: 15 Oct 2020
    8.1
    High

    CVE-2020-27157

    Last Modified: 21 Nov 2024

    Veritas APTARE versions prior to 10.5 included code that bypassed the normal login process when specific authentication credentials were provided to the server. An unauthenticated user could login to the application and gain access to the data and functionality accessible to the targeted user account.

    Published: 15 Oct 2020
    8.8
    High

    CVE-2020-5642

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 15 Oct 2020
    6.1
    Medium

    CVE-2020-6365

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the victim or to redirect users to untrusted web pages containing malware or similar malicious exploits.

    Published: 15 Oct 2020
    5.5
    Medium

    CVE-2020-6376

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 15 Oct 2020
    7.8
    High

    CVE-2020-6374

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 15 Oct 2020
    5.5
    Medium

    CVE-2020-6375

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 15 Oct 2020
    7.8
    High

    CVE-2020-6373

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 15 Oct 2020
    7.8
    High

    CVE-2020-6372

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 15 Oct 2020
    4.3
    Medium

    CVE-2020-6371

    Last Modified: 21 Nov 2024

    User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.

    Published: 15 Oct 2020
    10
    Critical

    CVE-2020-6364

    Last Modified: 21 Nov 2024

    SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.

    Published: 15 Oct 2020