CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2020-7735

    Last Modified: 21 Nov 2024

    The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-15394

    Last Modified: 21 Nov 2024

    The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-15521

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2019-11556

    Last Modified: 21 Nov 2024

    Pagure before 5.6 allows XSS via the templates/blame.html blame view.

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-26098

    Last Modified: 21 Nov 2024

    cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26099

    Last Modified: 21 Nov 2024

    cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-26100

    Last Modified: 21 Nov 2024

    chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-26101

    Last Modified: 21 Nov 2024

    In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26102

    Last Modified: 21 Nov 2024

    In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26103

    Last Modified: 21 Nov 2024

    In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26104

    Last Modified: 21 Nov 2024

    In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-26105

    Last Modified: 21 Nov 2024

    In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26106

    Last Modified: 21 Nov 2024

    cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26107

    Last Modified: 21 Nov 2024

    cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-26108

    Last Modified: 21 Nov 2024

    cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26109

    Last Modified: 21 Nov 2024

    cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-26110

    Last Modified: 21 Nov 2024

    cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-26111

    Last Modified: 21 Nov 2024

    cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-26112

    Last Modified: 21 Nov 2024

    The email quota cache in cPanel before 90.0.10 allows overwriting of files.

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-26113

    Last Modified: 21 Nov 2024

    cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-26114

    Last Modified: 21 Nov 2024

    cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2020-26115

    Last Modified: 21 Nov 2024

    cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).

    Published: 25 Sept 2020
    —
    Unknown

    CVE-2020-25726

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Sept 2020
    5.5
    Medium

    CVE-2020-25203

    Last Modified: 21 Nov 2024

    The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other application is able to load any website/web content into the application's context, which is shown as a full-screen overlay to the user.

    Published: 25 Sept 2020
    8.8
    High

    CVE-2020-23837

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.

    Published: 25 Sept 2020
    8.2
    High

    CVE-2020-24718

    Last Modified: 21 Nov 2024

    bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

    Published: 25 Sept 2020
    5.3
    Medium

    CVE-2020-24595

    Last Modified: 21 Nov 2024

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.

    Published: 25 Sept 2020
    9.6
    Critical

    CVE-2020-24594

    Last Modified: 21 Nov 2024

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.

    Published: 25 Sept 2020
    7.2
    High

    CVE-2020-24593

    Last Modified: 21 Nov 2024

    Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.

    Published: 25 Sept 2020
    5.3
    Medium

    CVE-2020-24592

    Last Modified: 21 Nov 2024

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.

    Published: 25 Sept 2020
    7.1
    High

    CVE-2020-24692

    Last Modified: 21 Nov 2024

    The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.

    Published: 25 Sept 2020
    8.8
    High

    CVE-2020-24621

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.

    Published: 25 Sept 2020
    5.3
    Medium

    CVE-2020-24615

    Last Modified: 21 Nov 2024

    Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-13387

    Last Modified: 21 Nov 2024

    Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.

    Published: 25 Sept 2020
    7.5
    High

    CVE-2020-12824

    Last Modified: 21 Nov 2024

    Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-11805

    Last Modified: 21 Nov 2024

    Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.

    Published: 25 Sept 2020
    6.1
    Medium

    CVE-2017-17477

    Last Modified: 21 Nov 2024

    Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.

    Published: 25 Sept 2020
    7.2
    High

    CVE-2019-7178

    Last Modified: 21 Nov 2024

    Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.

    Published: 25 Sept 2020
    7.2
    High

    CVE-2019-7177

    Last Modified: 21 Nov 2024

    Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.

    Published: 25 Sept 2020
    7.5
    High

    CVE-2018-10585

    Last Modified: 21 Nov 2024

    Pexip Infinity before 18 allows remote Denial of Service (XML parsing).

    Published: 25 Sept 2020
    7.5
    High

    CVE-2018-10432

    Last Modified: 21 Nov 2024

    Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-25749

    Last Modified: 21 Nov 2024

    The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

    Published: 25 Sept 2020
    8.1
    High

    CVE-2020-25748

    Last Modified: 21 Nov 2024

    A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.

    Published: 25 Sept 2020
    9.4
    Critical

    CVE-2020-25747

    Last Modified: 21 Nov 2024

    The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.

    Published: 25 Sept 2020
    9.8
    Critical

    CVE-2020-25223

    Last Modified: 7 Nov 2025

    A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

    Published: 25 Sept 2020
    6.5
    Medium

    CVE-2021-3596

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.

    Published: 25 Sept 2020
    7.2
    High

    CVE-2020-25643

    Last Modified: 21 Nov 2024

    A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Sept 2020
    7.8
    High

    CVE-2020-17365

    Last Modified: 21 Nov 2024

    Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.

    Published: 24 Sept 2020
    7.3
    High

    CVE-2020-15843

    Last Modified: 21 Nov 2024

    ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Install\ and %PROGRAMFILES%\ActiveFax\Terminal\. The folder permissions allow "Full Control" to "Everyone". An authenticated local attacker can exploit this to replace the TSClientB.exe binary in the Terminal directory, which is executed on logon for every user. Alternatively, the attacker can replace any of the binaries in the Client or Install directories. The latter requires additional user interaction, for example starting the client.

    Published: 24 Sept 2020
    5.4
    Medium

    CVE-2020-15162

    Last Modified: 21 Nov 2024

    In PrestaShop from version 1.5.0.0 and before version 1.7.6.8, users are allowed to send compromised files. These attachments allowed people to input malicious JavaScript which triggered an XSS payload. The problem is fixed in version 1.7.6.8.

    Published: 24 Sept 2020