CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-13957

    Last Modified: 21 Nov 2024

    Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

    Published: 12 Oct 2020
    7.5
    High

    CVE-2021-20230

    Last Modified: 21 Nov 2024

    A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authority, which is not the one accepted by the stunnel server, to access the tunneled service instead of being redirected to the address specified in the redirect option. The highest threat from this vulnerability is to confidentiality.

    Published: 11 Oct 2020
    9.8
    Critical

    CVE-2020-26948

    Last Modified: 21 Nov 2024

    Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.

    Published: 10 Oct 2020
    7.8
    High

    CVE-2020-26947

    Last Modified: 21 Nov 2024

    monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.

    Published: 10 Oct 2020
    6.1
    Medium

    CVE-2020-26934

    Last Modified: 21 Nov 2024

    phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

    Published: 10 Oct 2020
    9.8
    Critical

    CVE-2020-26935

    Last Modified: 21 Nov 2024

    An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject malicious SQL in to a query.

    Published: 10 Oct 2020
    4.3
    Medium

    CVE-2020-26932

    Last Modified: 21 Nov 2024

    debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

    Published: 10 Oct 2020
    8.1
    High

    CVE-2020-26945

    Last Modified: 21 Nov 2024

    MyBatis before 3.5.6 mishandles deserialization of object streams.

    Published: 10 Oct 2020
    5.9
    Medium

    CVE-2020-13955

    Last Modified: 21 Nov 2024

    HttpUtils#getURLConnection method disables explicitly hostname verification for HTTPS connections making clients vulnerable to man-in-the-middle attacks. Calcite uses internally this method to connect with Druid and Splunk so information leakage may happen when using the respective Calcite adapters. The method itself is in a utility class so people may use it to create vulnerable HTTPS connections for other applications. From Apache Calcite 1.26 onwards, the hostname verification will be performed using the default JVM truststore.

    Published: 9 Oct 2020
    6.7
    Medium

    CVE-2020-9105

    Last Modified: 21 Nov 2024

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to access and modify the memory of the device by doing a series of operations. Successful exploit may cause the service abnormal.

    Published: 9 Oct 2020
    8.8
    High

    CVE-2020-26522

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in mod/user/act_user.php in Garfield Petshop through 2020-10-01 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.

    Published: 9 Oct 2020
    6.1
    Medium

    CVE-2020-26162

    Last Modified: 21 Nov 2024

    Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.

    Published: 9 Oct 2020
    8.8
    High

    CVE-2020-15838

    Last Modified: 21 Nov 2024

    The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26897

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26898

    Last Modified: 21 Nov 2024

    NETGEAR RAX40 devices before 1.0.3.80 are affected by incorrect configuration of security settings.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26899

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26900

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26901

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26902

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26903

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26904

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26905

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26906

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26907

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

    Published: 9 Oct 2020
    9.4
    Critical

    CVE-2020-26908

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6020 before 1.0.0.42, R6050 before 1.0.1.22, JR6150 before 1.0.1.22, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R69002 before 1.2.0.62, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    8.8
    High

    CVE-2020-26909

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.58 and R7500v2 before 1.0.3.48.

    Published: 9 Oct 2020
    8.4
    High

    CVE-2020-26910

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2.15.25, and RBS850 before 3.2.15.25.

    Published: 9 Oct 2020
    8.3
    High

    CVE-2020-26911

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    7.5
    High

    CVE-2020-26912

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    6.8
    Medium

    CVE-2020-26913

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.63, R7800 before 1.0.2.60, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, SRK60 before 2.2.2.20, SRR60 before 2.2.2.20, SRS60 before 2.2.2.20, WN3000RPv2 before 1.0.0.78, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, WNR2000v5 before 1.0.0.70, XR450 before 2.3.2.40, and XR500 before 2.3.2.40.

    Published: 9 Oct 2020
    6.7
    Medium

    CVE-2020-26914

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    6
    Medium

    CVE-2020-26915

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7500v2 before 1.0.3.46, R7800 before 1.0.2.68, R8900 before 1.0.4.28, R9000 before 1.0.4.28, RAX120 before 1.0.0.78, RBK50 before 2.3.5.30, RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, XR500 before 2.3.2.56, and XR700 before 1.0.1.10.

    Published: 9 Oct 2020
    5.4
    Medium

    CVE-2020-26916

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.50, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    4.1
    Medium

    CVE-2020-26917

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.

    Published: 9 Oct 2020
    4.1
    Medium

    CVE-2020-26918

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects EX7000 before 1.0.1.78, R6250 before 1.0.4.34, R6400 before 1.0.1.46, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.8, R8300 before 1.0.2.128, and R8500 before 1.0.2.128.

    Published: 9 Oct 2020
    9.8
    Critical

    CVE-2020-26919

    Last Modified: 7 Nov 2025

    NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.

    Published: 9 Oct 2020
    8.8
    High

    CVE-2020-26920

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.3.110, SRR60 before 2.5.3.110, and SRS60 before 2.5.3.110.

    Published: 9 Oct 2020
    8.3
    High

    CVE-2020-26921

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3, and XS724EM before 1.0.1.3.

    Published: 9 Oct 2020
    6.4
    Medium

    CVE-2020-26922

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

    Published: 9 Oct 2020
    4.3
    Medium

    CVE-2020-26923

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by stored XSS. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

    Published: 9 Oct 2020
    3.1
    Low

    CVE-2020-26924

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC720 before 3.9.1.13 and WAC730 before 3.9.1.13.

    Published: 9 Oct 2020
    3.2
    Low

    CVE-2020-26925

    Last Modified: 21 Nov 2024

    NETGEAR GS808E devices before 1.7.1.0 are affected by denial of service.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26926

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    9.4
    Critical

    CVE-2020-26927

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.66, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, AC2100 before 1.2.0.62, AC2400 before 1.2.0.62, AC2600 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

    Published: 9 Oct 2020
    9.6
    Critical

    CVE-2020-26928

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.10, RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

    Published: 9 Oct 2020
    7.3
    High

    CVE-2020-26929

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

    Published: 9 Oct 2020
    3.3
    Low

    CVE-2020-26930

    Last Modified: 21 Nov 2024

    NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.

    Published: 9 Oct 2020
    5.9
    Medium

    CVE-2020-26931

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

    Published: 9 Oct 2020
    4.6
    Medium

    CVE-2020-13626

    Last Modified: 21 Nov 2024

    OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

    Published: 9 Oct 2020
    5.3
    Medium

    CVE-2020-7760

    Last Modified: 21 Nov 2024

    This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

    Published: 9 Oct 2020