CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2020-26388

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26389

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26390

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26391

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26392

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26393

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26396

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26397

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26398

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26399

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26400

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26401

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26402

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    7.4
    High

    CVE-2020-25638

    Last Modified: 23 Apr 2025

    A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26349

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26368

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26377

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26394

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    —
    Unknown

    CVE-2020-26403

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2020. Notes: none.

    Published: 1 Oct 2020
    4
    Medium

    CVE-2020-13336

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.

    Published: 30 Sept 2020
    5.4
    Medium

    CVE-2020-12869

    Last Modified: 21 Nov 2024

    RainbowFish PacsOne Server 6.8.4 allows XSS.

    Published: 30 Sept 2020
    8.1
    High

    CVE-2020-13952

    Last Modified: 21 Nov 2024

    In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the hashed version of the authenticated users’ password, and access to connection information including the plaintext password for the current connection. It would also be possible to run arbitrary methods on the database connection object for the Presto or Hive connection, allowing the user to bypass security controls internal to Superset. This vulnerability is present in every Apache Superset version < 0.37.2.

    Published: 30 Sept 2020
    7.8
    High

    CVE-2020-16234

    Last Modified: 21 Nov 2024

    In PLC WinProladder Version 3.28 and prior, a stack-based buffer overflow vulnerability can be exploited when a valid user opens a specially crafted file, which may allow an attacker to remotely execute arbitrary code.

    Published: 30 Sept 2020
    8.8
    High

    CVE-2020-12715

    Last Modified: 21 Nov 2024

    RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.

    Published: 30 Sept 2020
    9.8
    Critical

    CVE-2020-12870

    Last Modified: 21 Nov 2024

    RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

    Published: 30 Sept 2020
    7.8
    High

    CVE-2020-6654

    Last Modified: 21 Nov 2024

    A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.

    Published: 30 Sept 2020
    4.8
    Medium

    CVE-2020-25830

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.

    Published: 30 Sept 2020
    4.3
    Medium

    CVE-2020-25781

    Last Modified: 21 Nov 2024

    An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

    Published: 30 Sept 2020
    4.8
    Medium

    CVE-2020-25288

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitrary JavaScript.

    Published: 30 Sept 2020
    7.2
    High

    CVE-2020-15849

    Last Modified: 21 Nov 2024

    Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an administrative account could abuse this vulnerability to recover sensitive data from the application's database, allowing for authorization bypass and taking over additional accounts by means of modifying password-reset tokens stored in the database. Remote command execution is also possible by leveraging this to abuse the Yii framework's bizRule functionality, allowing for arbitrary PHP code to be executed by the application. Remote command execution is also possible by using this together with a separate insecure file upload vulnerability (CVE-2020-15488).

    Published: 30 Sept 2020
    7.5
    High

    CVE-2020-15488

    Last Modified: 21 Nov 2024

    Re:Desk 2.3 allows insecure file upload.

    Published: 30 Sept 2020
    9.8
    Critical

    CVE-2020-15487

    Last Modified: 21 Nov 2024

    Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote command execution is possible by using this SQL injection to update certain database values, which are then executed by a bizRule eval() function in the yii/framework/web/auth/CAuthManager.php file. Resultant authorization bypass is also possible, by recovering or modifying password hashes and password reset tokens, allowing for administrative privileges to be obtained.

    Published: 30 Sept 2020
    5.3
    Medium

    CVE-2020-19676

    Last Modified: 21 Nov 2024

    Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)

    Published: 30 Sept 2020
    5.7
    Medium

    CVE-2020-24721

    Last Modified: 21 Nov 2024

    An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-09-29, as used in COVID-19 applications on Android and iOS. It allows a user to be put in a position where he or she can be coerced into proving or disproving an exposure notification, because of the persistent state of a private framework.

    Published: 30 Sept 2020
    9.8
    Critical

    CVE-2020-19672

    Last Modified: 21 Nov 2024

    Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.

    Published: 30 Sept 2020
    5.4
    Medium

    CVE-2019-18991

    Last Modified: 21 Nov 2024

    A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

    Published: 30 Sept 2020
    5.4
    Medium

    CVE-2019-18990

    Last Modified: 21 Nov 2024

    A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

    Published: 30 Sept 2020
    5.4
    Medium

    CVE-2019-18989

    Last Modified: 21 Nov 2024

    A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

    Published: 30 Sept 2020
    7.5
    High

    CVE-2020-13951

    Last Modified: 21 Nov 2024

    Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

    Published: 30 Sept 2020
    4.9
    Medium

    CVE-2020-19670

    Last Modified: 21 Nov 2024

    In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any passwords.

    Published: 30 Sept 2020
    5.3
    Medium

    CVE-2020-13953

    Last Modified: 21 Nov 2024

    In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.

    Published: 30 Sept 2020
    9.1
    Critical

    CVE-2020-12506

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW03 allows an attacker to change the settings of the devices by sending specifically constructed requests without authentication This issue affects: WAGO 750-362, WAGO 750-363, WAGO 750-823, WAGO 750-832/xxx-xxx, WAGO 750-862, WAGO 750-891, WAGO 750-890/xxx-xxx in versions FW03 and prior versions.

    Published: 30 Sept 2020
    8.2
    High

    CVE-2020-12505

    Last Modified: 21 Nov 2024

    Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx, WAGO 750-881, WAGO 750-831/xxx-xxx, WAGO 750-882, WAGO 750-885/xxx-xxx, WAGO 750-889 in versions FW07 and below.

    Published: 30 Sept 2020
    8.8
    High

    CVE-2020-21564

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck CMS 4.7.10-dev2 and 4.7.11. There is a file upload vulnerability that can cause a remote command execution via admin.php?action=files.

    Published: 30 Sept 2020
    8.8
    High

    CVE-2020-26163

    Last Modified: 21 Nov 2024

    BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.

    Published: 30 Sept 2020
    7.7
    High

    CVE-2020-21527

    Last Modified: 21 Nov 2024

    There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.

    Published: 30 Sept 2020
    9.8
    Critical

    CVE-2020-21526

    Last Modified: 21 Nov 2024

    An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.

    Published: 30 Sept 2020
    7.5
    High

    CVE-2020-21525

    Last Modified: 21 Nov 2024

    Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.

    Published: 30 Sept 2020
    3.3
    Low

    CVE-2020-4629

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.

    Published: 30 Sept 2020
    9.1
    Critical

    CVE-2020-21524

    Last Modified: 21 Nov 2024

    There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml file, but it is not used for security defense, This vulnerability can detect the intranet, read files, enable ddos attacks, etc. exp:https://github.com/halo-dev/halo/issues/423

    Published: 30 Sept 2020