CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-15979

    Last Modified: 21 Nov 2024

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-15984

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.

    Published: 6 Oct 2020
    5.5
    Medium

    CVE-2020-26571

    Last Modified: 21 Nov 2024

    The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.

    Published: 6 Oct 2020
    6.5
    Medium

    CVE-2020-6557

    Last Modified: 21 Nov 2024

    Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 6 Oct 2020
    5.9
    Medium

    CVE-2020-15237

    Last Modified: 21 Nov 2024

    In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated signature in constant time, using `Rack::Utils.secure_compare`. Users using the `derivation_endpoint` plugin are urged to upgrade to Shrine 3.3.0 or greater. A possible workaround is provided in the linked advisory.

    Published: 5 Oct 2020
    9.8
    Critical

    CVE-2020-16226

    Last Modified: 21 Nov 2024

    Multiple Mitsubishi Electric products are vulnerable to impersonations of a legitimate device by a malicious actor, which may allow an attacker to remotely execute arbitrary commands.

    Published: 5 Oct 2020
    9.8
    Critical

    CVE-2020-24231

    Last Modified: 21 Nov 2024

    Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans from a remote host using MLet that leads to arbitrary code execution.

    Published: 5 Oct 2020
    5.9
    Medium

    CVE-2020-15235

    Last Modified: 21 Nov 2024

    In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone except admins. All versions after commit f3dc89b9f6ab1544a289b3efc06699b13d63e0bd(3/10/20) are patched.

    Published: 5 Oct 2020
    8.6
    High

    CVE-2020-15236

    Last Modified: 21 Nov 2024

    In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can potentially read any file on the file system by crafting a special URL that allows for directory traversal. This is only possible when a storage module implementing local asset cache (e.g Local File System or Git) is enabled and that no web application firewall solution (e.g. cloudflare) strips potentially malicious URLs. Commit 084dcd69d1591586ee4752101e675d5f0ac6dcdc fixes this vulnerability by sanitizing the path before it is passed on to the storage module. The sanitization step removes any directory traversal (e.g. `..` and `.`) sequences as well as invalid filesystem characters from the path. As a workaround, disable any storage module with local asset caching capabilities such as Local File System and Git.

    Published: 5 Oct 2020
    9.8
    Critical

    CVE-2020-6875

    Last Modified: 21 Nov 2024

    A ZTE product is impacted by the improper access control vulnerability. Due to lack of an authentication protection mechanism in the program, attackers could use this vulnerability to gain access right through brute-force attacks. This affects: <ZXONE 19700 SNPE><ZXONE8700V1.40R2B13_SNPE>

    Published: 5 Oct 2020
    8.8
    High

    CVE-2020-26048

    Last Modified: 21 Nov 2024

    The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

    Published: 5 Oct 2020
    5.5
    Medium

    CVE-2020-0571

    Last Modified: 21 Nov 2024

    Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silver Processor Series may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 5 Oct 2020
    4.4
    Medium

    CVE-2019-14556

    Last Modified: 21 Nov 2024

    Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow a privileged user to potentially enable denial of service via local access.

    Published: 5 Oct 2020
    5.5
    Medium

    CVE-2020-8671

    Last Modified: 21 Nov 2024

    Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Celeron(R) Processor 4000 Series may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 5 Oct 2020
    7.8
    High

    CVE-2020-12302

    Last Modified: 21 Nov 2024

    Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 5 Oct 2020
    8
    High

    CVE-2019-14557

    Last Modified: 21 Nov 2024

    Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.

    Published: 5 Oct 2020
    7.5
    High

    CVE-2020-26061

    Last Modified: 21 Nov 2024

    ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.

    Published: 5 Oct 2020
    9.8
    Critical

    CVE-2020-4493

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow an attacker to bypass authentication and issue commands using a specially crafted HTTP command. IBM X-Force ID: 181995.

    Published: 5 Oct 2020
    8
    High

    CVE-2020-8182

    Last Modified: 21 Nov 2024

    Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.

    Published: 5 Oct 2020
    6.5
    Medium

    CVE-2020-8223

    Last Modified: 21 Nov 2024

    A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

    Published: 5 Oct 2020
    4.3
    Medium

    CVE-2020-8235

    Last Modified: 21 Nov 2024

    Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.

    Published: 5 Oct 2020
    5.3
    Medium

    CVE-2020-8228

    Last Modified: 21 Nov 2024

    A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.

    Published: 5 Oct 2020
    5.4
    Medium

    CVE-2020-26166

    Last Modified: 21 Nov 2024

    The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

    Published: 5 Oct 2020
    6
    Medium

    CVE-2020-7709

    Last Modified: 5 Mar 2025

    This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.

    Published: 5 Oct 2020
    9.8
    Critical

    CVE-2020-27619

    Last Modified: 21 Nov 2024

    In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

    Published: 5 Oct 2020
    7.5
    High

    CVE-2017-18924

    Last Modified: 21 Nov 2024

    oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.

    Published: 4 Oct 2020
    7.8
    High

    CVE-2020-25776

    Last Modified: 21 Nov 2024

    Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 2 Oct 2020
    7.1
    High

    CVE-2020-5988

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which allocated memory can be freed twice, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    5.5
    Medium

    CVE-2020-5989

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    7.1
    High

    CVE-2020-5985

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    5.5
    Medium

    CVE-2020-5986

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-5987

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writable by the guest after the plugin has validated them, which may lead to the guest being able to pass invalid parameters to plugin handlers, which may lead to denial of service or escalation of privileges. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    7.1
    High

    CVE-2020-5983

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin and the host driver kernel module, in which the potential exists to write to a memory location that is outside the intended boundary of the frame buffer memory allocated to guest operating systems, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-5984

    Last Modified: 21 Nov 2024

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerability while freeing some resources, which may lead to denial of service, code execution, and information disclosure. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-15233

    Last Modified: 21 Nov 2024

    ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can override the registered redirect URL by performing an OAuth flow and requesting a redirect URL that is to the loopback adapter. Attackers can provide both custom URL query parameters to their loopback redirect URL, as well as actually overriding the host of the registered redirect URL. These attacks are only applicable in scenarios where the attacker has access over the loopback interface. This vulnerability has been patched in ORY Fosite v0.34.1.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-15234

    Last Modified: 21 Nov 2024

    ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint where compared using strings.ToLower while they should have been compared with a simple string match. This allows an attacker to register a client with allowed redirect URL https://example.com/callback. Then perform an OAuth2 flow and requesting redirect URL https://example.com/CALLBACK. Instead of an error (invalid redirect URL), the browser is redirected to https://example.com/CALLBACK with a potentially successful OAuth2 response, depending on the state of the overall OAuth2 flow (the user might still deny the request for example). This vulnerability has been patched in ORY Fosite v0.34.1.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26527

    Last Modified: 21 Nov 2024

    An issue was discovered in API/api/Version in Damstra Smart Asset 2020.7. Cross-origin resource sharing trusts random origins by accepting the arbitrary 'Origin: example.com' header and responding with 200 OK and a wildcard 'Access-Control-Allow-Origin: *' header.

    Published: 2 Oct 2020
    5.3
    Medium

    CVE-2020-26526

    Last Modified: 21 Nov 2024

    An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").

    Published: 2 Oct 2020
    9.1
    Critical

    CVE-2020-26525

    Last Modified: 21 Nov 2024

    Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

    Published: 2 Oct 2020
    9.3
    Critical

    CVE-2020-15232

    Last Modified: 21 Nov 2024

    In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.

    Published: 2 Oct 2020
    9.1
    Critical

    CVE-2020-12676

    Last Modified: 21 Nov 2024

    FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".

    Published: 2 Oct 2020
    9.3
    Critical

    CVE-2020-15231

    Last Modified: 21 Nov 2024

    In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.

    Published: 2 Oct 2020
    5.4
    Medium

    CVE-2020-13338

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

    Published: 2 Oct 2020
    7.2
    High

    CVE-2020-13337

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

    Published: 2 Oct 2020
    8.1
    High

    CVE-2020-15589

    Last Modified: 21 Nov 2024

    A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS certificate validation, leading to a man-in-the-middle attack against HTTPS and unauthenticated remote code execution.

    Published: 2 Oct 2020
    7.2
    High

    CVE-2020-24397

    Last Modified: 21 Nov 2024

    An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.

    Published: 2 Oct 2020
    8.5
    High

    CVE-2020-15230

    Last Modified: 21 Nov 2024

    Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4.

    Published: 2 Oct 2020
    8.8
    High

    CVE-2020-24628

    Last Modified: 21 Nov 2024

    A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

    Published: 2 Oct 2020
    5.4
    Medium

    CVE-2020-24627

    Last Modified: 21 Nov 2024

    A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

    Published: 2 Oct 2020
    6.5
    Medium

    CVE-2020-24568

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.

    Published: 2 Oct 2020