CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-5981

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, which may lead to denial of service or code execution.

    Published: 2 Oct 2020
    4.4
    Medium

    CVE-2020-5982

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests, which may lead to denial of service.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-5979

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which a user is presented with a dialog box for input by a high-privilege process, which may lead to escalation of privileges.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-5980

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in multiple components in which a securely loaded system DLL will load its dependencies in an insecure fashion, which may lead to code execution or denial of service.

    Published: 2 Oct 2020
    6.5
    Medium

    CVE-2020-5422

    Last Modified: 21 Nov 2024

    BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

    Published: 2 Oct 2020
    6.4
    Medium

    CVE-2020-24356

    Last Modified: 21 Nov 2024

    `cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which could be abused by a malicious entity to execute commands as a privileged user. Version 2020.8.1 fixes this issue.

    Published: 2 Oct 2020
    9.1
    Critical

    CVE-2020-18191

    Last Modified: 21 Nov 2024

    GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php

    Published: 2 Oct 2020
    9.1
    Critical

    CVE-2020-18190

    Last Modified: 21 Nov 2024

    Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-18185

    Last Modified: 21 Nov 2024

    class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

    Published: 2 Oct 2020
    7.2
    High

    CVE-2020-18184

    Last Modified: 21 Nov 2024

    In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.

    Published: 2 Oct 2020
    8.3
    High

    CVE-2020-7738

    Last Modified: 21 Nov 2024

    All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().

    Published: 2 Oct 2020
    5.9
    Medium

    CVE-2020-8110

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-supplied data, which can result in a pointer that is fetched from uninitialized memory. This can lead to denial-of-service. This issue affects: Bitdefender Engines version 7.84897 and prior versions.

    Published: 2 Oct 2020
    7.3
    High

    CVE-2020-7737

    Last Modified: 21 Nov 2024

    All versions of package safetydance are vulnerable to Prototype Pollution via the set function.

    Published: 2 Oct 2020
    7.3
    High

    CVE-2020-7736

    Last Modified: 21 Nov 2024

    The package bmoor before 0.8.12 are vulnerable to Prototype Pollution via the set function.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-13168

    Last Modified: 21 Nov 2024

    SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-26135

    Last Modified: 21 Nov 2024

    Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-26134

    Last Modified: 21 Nov 2024

    Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.

    Published: 2 Oct 2020
    8.8
    High

    CVE-2020-26124

    Last Modified: 21 Nov 2024

    openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-24698

    Last Modified: 21 Nov 2024

    An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a crash or possibly arbitrary code execution. by sending crafted queries with a GSS-TSIG signature.

    Published: 2 Oct 2020
    7.5
    High

    CVE-2020-24697

    Last Modified: 21 Nov 2024

    An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can cause a denial of service by sending crafted queries with a GSS-TSIG signature.

    Published: 2 Oct 2020
    8.1
    High

    CVE-2020-24696

    Last Modified: 21 Nov 2024

    An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG signature.

    Published: 2 Oct 2020
    4.3
    Medium

    CVE-2020-17482

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-17382

    Last Modified: 21 Nov 2024

    The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-14294

    Last Modified: 21 Nov 2024

    An issue was discovered in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.

    Published: 2 Oct 2020
    7.5
    High

    CVE-2020-14293

    Last Modified: 21 Nov 2024

    conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).

    Published: 2 Oct 2020
    7.5
    High

    CVE-2020-12127

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-12126

    Last Modified: 21 Nov 2024

    Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-12125

    Last Modified: 21 Nov 2024

    A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-12124

    Last Modified: 21 Nov 2024

    A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

    Published: 2 Oct 2020
    8.1
    High

    CVE-2020-12123

    Last Modified: 21 Nov 2024

    CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.

    Published: 2 Oct 2020
    7.4
    High

    CVE-2019-19199

    Last Modified: 21 Nov 2024

    REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26534

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26535

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to a write access violation (and read access violation).

    Published: 2 Oct 2020
    5.5
    Medium

    CVE-2020-26536

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is a NULL pointer dereference via a crafted PDF document.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26537

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. In a certain Shading calculation, the number of outputs is unequal to the number of color components in a color space. This causes an out-of-bounds write.

    Published: 2 Oct 2020
    7.8
    High

    CVE-2020-26538

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in the current working directory.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26539

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1. When there is a multiple interpretation error for /V (in the Additional Action and Field dictionaries), a use-after-free can occur with resultant remote code execution (or an information leak).

    Published: 2 Oct 2020
    7.5
    High

    CVE-2020-26540

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.

    Published: 2 Oct 2020
    5.3
    Medium

    CVE-2020-26524

    Last Modified: 21 Nov 2024

    CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.

    Published: 2 Oct 2020
    6.1
    Medium

    CVE-2020-26523

    Last Modified: 21 Nov 2024

    Froala Editor before 3.2.2 allows XSS via pasted content.

    Published: 2 Oct 2020
    5.5
    Medium

    CVE-2020-26519

    Last Modified: 21 Nov 2024

    Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.

    Published: 2 Oct 2020
    9.8
    Critical

    CVE-2020-26518

    Last Modified: 21 Nov 2024

    Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

    Published: 2 Oct 2020
    7.5
    High

    CVE-2020-26511

    Last Modified: 21 Nov 2024

    The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.

    Published: 2 Oct 2020
    6.4
    Medium

    CVE-2021-37159

    Last Modified: 21 Nov 2024

    hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

    Published: 2 Oct 2020
    2.3
    Low

    CVE-2020-5387

    Last Modified: 21 Nov 2024

    Dell XPS 13 9370 BIOS versions prior to 1.13.1 contains an Improper Exception Handling vulnerability. A local attacker with physical access could exploit this vulnerability to prevent the system from booting until the exploited boot device is removed.

    Published: 1 Oct 2020
    7.5
    High

    CVE-2020-9491

    Last Modified: 21 Nov 2024

    In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However intracluster communication such as cluster request replication, Site-to-Site, and load balanced queues continued to support TLS v1.0 or v1.1.

    Published: 1 Oct 2020
    5.5
    Medium

    CVE-2020-13940

    Last Modified: 21 Nov 2024

    In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted administrators to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE).

    Published: 1 Oct 2020
    7.5
    High

    CVE-2020-9487

    Last Modified: 21 Nov 2024

    In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to use the token to access the content. An unauthenticated user could repeatedly request download tokens, preventing legitimate users from requesting download tokens.

    Published: 1 Oct 2020
    7.5
    High

    CVE-2020-9486

    Last Modified: 21 Nov 2024

    In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON was printed, potentially containing sensitive values in plaintext.

    Published: 1 Oct 2020
    6.5
    Medium

    CVE-2020-5788

    Last Modified: 21 Nov 2024

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action.

    Published: 1 Oct 2020