CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-19200

    Last Modified: 21 Nov 2024

    REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.

    Published: 6 Oct 2020
    4.2
    Medium

    CVE-2020-25803

    Last Modified: 21 Nov 2024

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker template exposed objects. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.

    Published: 6 Oct 2020
    4.2
    Medium

    CVE-2020-25802

    Last Modified: 21 Nov 2024

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy scripting. This issue affects: Crafter Software Crafter CMS 3.0 versions prior to 3.0.27; 3.1 versions prior to 3.1.7.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-8782

    Last Modified: 21 Nov 2024

    Unauthenticated RPC server on ALEOS before 4.4.9, 4.9.5, and 4.14.0 allows remote code execution.

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-8781

    Last Modified: 21 Nov 2024

    Lack of input sanitization in UpdateRebootMgr service of ALEOS 4.11 and later allow an escalation to root from a low-privilege process.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-7466

    Last Modified: 21 Nov 2024

    The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-7465

    Last Modified: 21 Nov 2024

    The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-15598

    Last Modified: 3 Jul 2025

    Trustwave ModSecurity 3.x through 3.0.4 allows denial of service via a special request. NOTE: The discoverer reports "Trustwave has signaled they are disputing our claims." The CVE suggests that there is a security issue with how ModSecurity handles regular expressions that can result in a Denial of Service condition. The vendor does not consider this as a security issue because1) there is no default configuration issue here. An attacker would need to know that a rule using a potentially problematic regular expression was in place, 2) the attacker would need to know the basic nature of the regular expression itself to exploit any resource issues. It's well known that regular expression usage can be taxing on system resources regardless of the use case. It is up to the administrator to decide on when it is appropriate to trade resources for potential security benefit

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-24219

    Last Modified: 21 Nov 2024

    An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-24218

    Last Modified: 21 Nov 2024

    An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-24217

    Last Modified: 21 Nov 2024

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-24216

    Last Modified: 21 Nov 2024

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be private.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-24215

    Last Modified: 21 Nov 2024

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uploading a custom firmware update, to ultimately achieve arbitrary code execution.

    Published: 6 Oct 2020
    9.8
    Critical

    CVE-2020-24214

    Last Modified: 21 Nov 2024

    An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for up to a minute, until it automatically reboots. Attackers can send malicious requests once a minute, effectively disabling the device.

    Published: 6 Oct 2020
    6.1
    Medium

    CVE-2020-23832

    Last Modified: 21 Nov 2024

    A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-25986

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-25987

    Last Modified: 21 Nov 2024

    MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

    Published: 6 Oct 2020
    6.6
    Medium

    CVE-2020-14355

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-5632

    Last Modified: 21 Nov 2024

    InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1) allow authenticated attackers to bypass access restriction and to execute arbitrary code with an elevated privilege via a specially crafted executable files.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-5634

    Last Modified: 21 Nov 2024

    ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware versions prior to v1.14, and WRC-1167GST2 firmware versions prior to v1.10) allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified vectors.

    Published: 6 Oct 2020
    6.1
    Medium

    CVE-2020-5631

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.

    Published: 6 Oct 2020
    5.7
    Medium

    CVE-2020-27825

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.

    Published: 6 Oct 2020
    9
    Critical

    CVE-2020-15180

    Last Modified: 21 Nov 2024

    A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15969

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15974

    Last Modified: 21 Nov 2024

    Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15981

    Last Modified: 21 Nov 2024

    Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15985

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 6 Oct 2020
    6.3
    Medium

    CVE-2020-15988

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15990

    Last Modified: 21 Nov 2024

    Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-26572

    Last Modified: 21 Nov 2024

    The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15967

    Last Modified: 21 Nov 2024

    Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15970

    Last Modified: 21 Nov 2024

    Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15971

    Last Modified: 21 Nov 2024

    Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15972

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15975

    Last Modified: 21 Nov 2024

    Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15976

    Last Modified: 21 Nov 2024

    Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15977

    Last Modified: 21 Nov 2024

    Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-15980

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15982

    Last Modified: 21 Nov 2024

    Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 6 Oct 2020
    7.8
    High

    CVE-2020-15983

    Last Modified: 21 Nov 2024

    Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15986

    Last Modified: 21 Nov 2024

    Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15987

    Last Modified: 21 Nov 2024

    Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted WebRTC stream.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-15989

    Last Modified: 21 Nov 2024

    Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15991

    Last Modified: 21 Nov 2024

    Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15992

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-26570

    Last Modified: 21 Nov 2024

    The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.

    Published: 6 Oct 2020
    7.5
    High

    CVE-2020-26575

    Last Modified: 21 Nov 2024

    In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15968

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15973

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.

    Published: 6 Oct 2020
    8.8
    High

    CVE-2020-15978

    Last Modified: 21 Nov 2024

    Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.

    Published: 6 Oct 2020