CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2020-21523

    Last Modified: 21 Nov 2024

    A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign test="freemarker.template.utility.Execute"?new()> ${test("touch /tmp/freemarkerPwned")}

    Published: 30 Sept 2020
    9.8
    Critical

    CVE-2020-21522

    Last Modified: 21 Nov 2024

    An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.

    Published: 30 Sept 2020
    4.9
    Medium

    CVE-2020-21244

    Last Modified: 21 Nov 2024

    An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.

    Published: 30 Sept 2020
    3.5
    Low

    CVE-2019-17098

    Last Modified: 21 Nov 2024

    Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August Connect Wi-Fi Bridge App version v10.11.0 and prior versions on Android. August Connect Firmware version 2.2.12 and prior versions.

    Published: 30 Sept 2020
    6.1
    Medium

    CVE-2020-22481

    Last Modified: 21 Nov 2024

    An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information.

    Published: 30 Sept 2020
    7.5
    High

    CVE-2020-26149

    Last Modified: 21 Nov 2024

    NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

    Published: 30 Sept 2020
    3.2
    Low

    CVE-2020-15731

    Last Modified: 21 Nov 2024

    An improper Input Validation vulnerability in the code handling file renaming and recovery in Bitdefender Engines allows an attacker to write an arbitrary file in a location hardcoded in a specially-crafted malicious file name. This issue affects: Bitdefender Engines versions prior to 7.85448.

    Published: 30 Sept 2020
    5.3
    Medium

    CVE-2020-5132

    Last Modified: 21 Nov 2024

    SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

    Published: 30 Sept 2020
    9.6
    Critical

    CVE-2020-26157

    Last Modified: 21 Nov 2024

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node integration.

    Published: 30 Sept 2020
    9.6
    Critical

    CVE-2020-26158

    Last Modified: 21 Nov 2024

    Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

    Published: 30 Sept 2020
    5.4
    Medium

    CVE-2020-22842

    Last Modified: 21 Nov 2024

    CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.

    Published: 30 Sept 2020
    5.5
    Medium

    CVE-2020-25641

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 30 Sept 2020
    5.5
    Medium

    CVE-2020-10762

    Last Modified: 21 Nov 2024

    An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

    Published: 30 Sept 2020
    6.7
    Medium

    CVE-2020-25637

    Last Modified: 21 Nov 2024

    A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL permissions could use this flaw to crash the libvirt daemon, resulting in a denial of service, or potentially escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 30 Sept 2020
    5.5
    Medium

    CVE-2020-10763

    Last Modified: 21 Nov 2024

    An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.

    Published: 30 Sept 2020
    6.8
    Medium

    CVE-2020-25816

    Last Modified: 21 Nov 2024

    HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.

    Published: 30 Sept 2020
    6.1
    Medium

    CVE-2020-25626

    Last Modified: 21 Nov 2024

    A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a cross-site-scripting (XSS) vulnerability.

    Published: 30 Sept 2020
    7.5
    High

    CVE-2020-26150

    Last Modified: 21 Nov 2024

    info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

    Published: 29 Sept 2020
    4.3
    Medium

    CVE-2020-13794

    Last Modified: 21 Nov 2024

    Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.

    Published: 29 Sept 2020
    —
    Unknown

    CVE-2020-13506

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 29 Sept 2020
    9.8
    Critical

    CVE-2018-5353

    Last Modified: 21 Nov 2024

    The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required

    Published: 29 Sept 2020
    8.8
    High

    CVE-2018-5354

    Last Modified: 21 Nov 2024

    The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP.

    Published: 29 Sept 2020
    6.5
    Medium

    CVE-2020-24570

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.

    Published: 29 Sept 2020
    4.3
    Medium

    CVE-2020-24569

    Last Modified: 21 Nov 2024

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.

    Published: 29 Sept 2020
    9.8
    Critical

    CVE-2020-25763

    Last Modified: 21 Nov 2024

    Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.

    Published: 29 Sept 2020
    9.1
    Critical

    CVE-2020-25762

    Last Modified: 21 Nov 2024

    An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.

    Published: 29 Sept 2020
    6.1
    Medium

    CVE-2020-25761

    Last Modified: 23 Jan 2026

    Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.

    Published: 29 Sept 2020
    8.8
    High

    CVE-2020-25760

    Last Modified: 23 Jan 2026

    Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

    Published: 29 Sept 2020
    8.3
    High

    CVE-2020-25017

    Last Modified: 21 Nov 2024

    Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header.

    Published: 29 Sept 2020
    7.5
    High

    CVE-2020-25018

    Last Modified: 21 Nov 2024

    Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization.

    Published: 29 Sept 2020
    8
    High

    CVE-2020-13658

    Last Modified: 21 Nov 2024

    In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.

    Published: 29 Sept 2020
    7.5
    High

    CVE-2020-26148

    Last Modified: 21 Nov 2024

    md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.

    Published: 29 Sept 2020
    4.3
    Medium

    CVE-2020-13326

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.

    Published: 29 Sept 2020
    8.3
    High

    CVE-2020-13321

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.

    Published: 29 Sept 2020
    6.5
    Medium

    CVE-2020-13324

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

    Published: 29 Sept 2020
    7.1
    High

    CVE-2020-13325

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

    Published: 29 Sept 2020
    7.7
    High

    CVE-2020-13323

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

    Published: 29 Sept 2020
    5.4
    Medium

    CVE-2020-13331

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

    Published: 29 Sept 2020
    4.4
    Medium

    CVE-2020-13330

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

    Published: 29 Sept 2020
    6.5
    Medium

    CVE-2020-13329

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.

    Published: 29 Sept 2020
    4.8
    Medium

    CVE-2020-13328

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.

    Published: 29 Sept 2020
    6.5
    Medium

    CVE-2020-13320

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.

    Published: 29 Sept 2020
    7.2
    High

    CVE-2020-13322

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.

    Published: 29 Sept 2020
    5.3
    Medium

    CVE-2020-15216

    Last Modified: 21 Nov 2024

    In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A patch is available, all users of goxmldsig should upgrade to at least revision f6188febf0c29d7ffe26a0436212b19cb9615e64 or version 1.1.0

    Published: 29 Sept 2020
    4.3
    Medium

    CVE-2020-13319

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.

    Published: 29 Sept 2020
    6.5
    Medium

    CVE-2020-13296

    Last Modified: 21 Nov 2024

    An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

    Published: 29 Sept 2020
    9.8
    Critical

    CVE-2020-20800

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.

    Published: 29 Sept 2020
    7.8
    High

    CVE-2020-4607

    Last Modified: 21 Nov 2024

    IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security restrictions due to improper input validation. IBM X-Force ID: 184884.

    Published: 29 Sept 2020
    6.1
    Medium

    CVE-2020-26043

    Last Modified: 21 Nov 2024

    An issue was discovered in Hoosk CMS v1.8.0. There is a XSS vulnerability in install/index.php

    Published: 29 Sept 2020
    7.2
    High

    CVE-2020-8243

    Last Modified: 30 Oct 2025

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

    Published: 29 Sept 2020