CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2020-26858

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26859

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26860

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26861

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26863

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26864

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26865

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26866

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    7.3
    High

    CVE-2020-7743

    Last Modified: 21 Nov 2024

    The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

    Published: 7 Oct 2020
    6.1
    Medium

    CVE-2020-8264

    Last Modified: 21 Nov 2024

    In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26843

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26853

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    —
    Unknown

    CVE-2020-26862

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 7 Oct 2020
    4.3
    Medium

    CVE-2020-14183

    Last Modified: 21 Nov 2024

    Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-16267

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15927

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26600

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Auto Hotspot allows attackers to obtain sensitive information. The Samsung ID is SVE-2020-17288 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26601

    Last Modified: 21 Nov 2024

    An issue was discovered in DirEncryptService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileged action via a modified intent. The Samsung ID is SVE-2020-18034 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26602

    Last Modified: 21 Nov 2024

    An issue was discovered in EthernetNetwork on Samsung mobile devices with O(8.1), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows sdcard access by an unprivileged process. The Samsung ID is SVE-2020-18392 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26604

    Last Modified: 21 Nov 2024

    An issue was discovered in SystemUI on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. PendingIntent allows an unprivileged process to access contact numbers. The Samsung ID is SVE-2020-18467 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26605

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The Samsung ID is SVE-2020-18596 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26606

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. An attacker can access certain Secure Folder content via a debugging command. The Samsung ID is SVE-2020-18673 (October 2020).

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-26607

    Last Modified: 21 Nov 2024

    An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileged action via a modified intent. The Samsung ID is SVE-2020-18418 (October 2020).

    Published: 6 Oct 2020
    5.3
    Medium

    CVE-2020-26603

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivileged process to read arbitrary files. The Samsung ID is SVE-2020-18433 (October 2020).

    Published: 6 Oct 2020
    5.3
    Medium

    CVE-2020-26599

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentication. The Samsung ID is SVE-2020-17079 (October 2020).

    Published: 6 Oct 2020
    3.5
    Low

    CVE-2020-15239

    Last Modified: 21 Nov 2024

    In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other limitations on the outbound (GET) traffic. For example, in a scenario where a single server has multiple instances of the application running (with separate DATA_ROOT settings), an attacker who has knowledge about the directory structure is able to read files from any other instance to which the process has read access. If instances have individual authentication (for example, HTTP authentication via a reverse proxy, source IP based filtering) or other restrictions (such as quotas), attackers may circumvent those limits in such a scenario by using the Directory Traversal to retrieve data from the other instances. If the associated XMPP server (or anyone knowing the SECRET_KEY) is malicious, they can write files outside the DATA_ROOT. The files which are written are constrained to have the `.meta` and the `.data` suffixes; the `.meta` file will contain the JSON with the Content-Type of the original request and the `.data` file will contain the payload. The issue is patched in version 0.4.0.

    Published: 6 Oct 2020
    4.3
    Medium

    CVE-2020-13333

    Last Modified: 21 Nov 2024

    A potential DOS vulnerability was discovered in GitLab versions 13.1, 13.2 and 13.3. The api to update an asset as a link from a release had a regex check which caused exponential number of backtracks for certain user supplied values resulting in high CPU usage.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-13345

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 10.8. Reflected XSS on Multiple Routes

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-13343

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26597

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 9.0 and 10 software. The Wi-Fi subsystem has incorrect input validation, leading to a crash. The LG ID is LVE-SMP-200022 (October 2020).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26598

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, and 9.0 software. The Network Management component could allow an unauthorized actor to kill a TCP connection. The LG ID is LVE-SMP-200023 (October 2020).

    Published: 6 Oct 2020
    5.6
    Medium

    CVE-2020-15215

    Last Modified: 21 Nov 2024

    Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true` are affected. This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-1907

    Last Modified: 21 Nov 2024

    A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-1904

    Last Modified: 21 Nov 2024

    A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

    Published: 6 Oct 2020
    3.3
    Low

    CVE-2020-1905

    Last Modified: 21 Nov 2024

    Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-1906

    Last Modified: 21 Nov 2024

    A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-1903

    Last Modified: 21 Nov 2024

    An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-1902

    Last Modified: 21 Nov 2024

    A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP.

    Published: 6 Oct 2020
    5.3
    Medium

    CVE-2020-1901

    Last Modified: 21 Nov 2024

    Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-15174

    Last Modified: 21 Nov 2024

    In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites. The issue is patched in versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 As a workaround sandbox all your iframes using the sandbox attribute. This will prevent them creating top-frame navigations and is good practice anyway.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2019-4326

    Last Modified: 21 Nov 2024

    "HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."

    Published: 6 Oct 2020
    5.3
    Medium

    CVE-2019-4325

    Last Modified: 21 Nov 2024

    "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-24807

    Last Modified: 21 Nov 2024

    The socket.io-file package through 2.0.31 for Node.js relies on client-side validation of file types, which allows remote attackers to execute arbitrary code by uploading an executable file via a modified JSON name field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 6 Oct 2020
    8.2
    High

    CVE-2020-7740

    Last Modified: 21 Nov 2024

    This affects all versions of package node-pdf-generator. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-4528

    Last Modified: 21 Nov 2024

    IBM MQ Appliance (IBM DataPower Gateway 10.0.0.0 and 2018.4.1.0 through 2018.4.1.12) could allow a local user, under special conditions, to obtain highly sensitive information from log files. IBM X-Force ID: 182658.

    Published: 6 Oct 2020
    6.1
    Medium

    CVE-2019-4725

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172131.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-26582

    Last Modified: 21 Nov 2024

    D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).

    Published: 6 Oct 2020
    8.2
    High

    CVE-2020-7739

    Last Modified: 21 Nov 2024

    This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.

    Published: 6 Oct 2020
    9.6
    Critical

    CVE-2020-26574

    Last Modified: 21 Nov 2024

    Leostream Connection Broker 8.2.x is affected by stored XSS. An unauthenticated attacker can inject arbitrary JavaScript code via the webquery.pl User-Agent HTTP header. It is rendered by the admins the next time they log in. The JavaScript injected can be used to force the admin to upload a malicious Perl script that will be executed as root via libMisc::browser_client. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 6 Oct 2020
    9.9
    Critical

    CVE-2020-7741

    Last Modified: 21 Nov 2024

    This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).

    Published: 6 Oct 2020