CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-5787

    Last Modified: 21 Nov 2024

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action.

    Published: 1 Oct 2020
    6.1
    Medium

    CVE-2020-5785

    Last Modified: 21 Nov 2024

    Insufficient output sanitization in Teltonika firmware TRB2_R_00.02.04.3 allows an unauthenticated attacker to conduct reflected cross-site scripting via a crafted ‘action’ or ‘pkg_name’ parameter.

    Published: 1 Oct 2020
    8.8
    High

    CVE-2020-5786

    Last Modified: 21 Nov 2024

    Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

    Published: 1 Oct 2020
    6.5
    Medium

    CVE-2020-5789

    Last Modified: 21 Nov 2024

    Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

    Published: 1 Oct 2020
    6.5
    Medium

    CVE-2020-5784

    Last Modified: 21 Nov 2024

    Server-Side Request Forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a low privileged user to cause the application to perform HTTP GET requests to arbitrary URLs.

    Published: 1 Oct 2020
    6.1
    Medium

    CVE-2020-14223

    Last Modified: 21 Nov 2024

    HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.

    Published: 1 Oct 2020
    8.7
    High

    CVE-2020-15227

    Last Modified: 21 Nov 2024

    Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

    Published: 1 Oct 2020
    9.8
    Critical

    CVE-2020-15533

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

    Published: 1 Oct 2020
    4.3
    Medium

    CVE-2020-15665

    Last Modified: 21 Nov 2024

    Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80.

    Published: 1 Oct 2020
    6.5
    Medium

    CVE-2020-15666

    Last Modified: 19 Aug 2026

    When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

    Published: 1 Oct 2020
    4.3
    Medium

    CVE-2020-15668

    Last Modified: 19 Aug 2026

    A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

    Published: 1 Oct 2020
    3.1
    Low

    CVE-2020-15671

    Last Modified: 19 Aug 2026

    When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.

    Published: 1 Oct 2020
    8.8
    High

    CVE-2020-15674

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81.

    Published: 1 Oct 2020
    8.8
    High

    CVE-2020-15675

    Last Modified: 21 Nov 2024

    When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.

    Published: 1 Oct 2020
    5.3
    Medium

    CVE-2020-25200

    Last Modified: 21 Nov 2024

    Pritunl 1.29.2145.25 allows attackers to enumerate valid VPN usernames via a series of /auth/session login attempts. Initially, the server will return error 401. However, if the username is valid, then after 20 login attempts, the server will start responding with error 400. Invalid usernames will receive error 401 indefinitely. Note: This has been disputed by the vendor as not a vulnerability. They argue that this is an intended design

    Published: 1 Oct 2020
    3.5
    Low

    CVE-2020-15228

    Last Modified: 21 Nov 2024

    In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format. Workflows that log untrusted data to stdout may invoke these commands, resulting in the path or environment variables being modified without the intention of the workflow or action author. The runner will release an update that disables the `set-env` and `add-path` workflow commands in the near future. For now, users should upgrade to `@actions/core v1.2.6` or later, and replace any instance of the `set-env` or `add-path` commands in their workflows with the new Environment File Syntax. Workflows and actions using the old commands or older versions of the toolkit will start to warn, then error out during workflow execution.

    Published: 1 Oct 2020
    6.1
    Medium

    CVE-2019-19393

    Last Modified: 21 Nov 2024

    The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.

    Published: 1 Oct 2020
    7.8
    High

    CVE-2020-24620

    Last Modified: 21 Nov 2024

    Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.

    Published: 1 Oct 2020
    7.5
    High

    CVE-2020-4576

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.5, 8.0, 8.5, and 9.0 traditional could allow a remote attacker to obtain sensitive information with a specially-crafted sequence of serialized objects. IBM X-Force ID: 184428.

    Published: 1 Oct 2020
    9.8
    Critical

    CVE-2020-25990

    Last Modified: 21 Nov 2024

    WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

    Published: 1 Oct 2020
    5.4
    Medium

    CVE-2020-24860

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.

    Published: 1 Oct 2020
    5.4
    Medium

    CVE-2020-24861

    Last Modified: 21 Nov 2024

    GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

    Published: 1 Oct 2020
    5.9
    Medium

    CVE-2020-8109

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in the ace.xmd parser that results from a lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. This can result in denial-of-service. This issue affects: Bitdefender Engines version 7.84892 and prior versions.

    Published: 1 Oct 2020
    5.4
    Medium

    CVE-2019-20903

    Last Modified: 21 Nov 2024

    The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.

    Published: 1 Oct 2020
    7.5
    High

    CVE-2019-20902

    Last Modified: 21 Nov 2024

    Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

    Published: 1 Oct 2020
    7.5
    High

    CVE-2020-11979

    Last Modified: 21 Nov 2024

    As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26313

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26340

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26350

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26359

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26369

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26378

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26386

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26395

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26404

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26314

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26315

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26316

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26317

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26318

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26319

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26320

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26321

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26322

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26323

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26324

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26325

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26326

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26327

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26328

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020