CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-25786

    Last Modified: 21 Nov 2024

    webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

    Published: 19 Sept 2020
    7.5
    High

    CVE-2020-25792

    Last Modified: 5 May 2025

    An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with pair().

    Published: 19 Sept 2020
    6.5
    Medium

    CVE-2020-8200

    Last Modified: 21 Nov 2024

    Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

    Published: 18 Sept 2020
    8.8
    High

    CVE-2020-8247

    Last Modified: 21 Nov 2024

    Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-8246

    Last Modified: 21 Nov 2024

    Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to a denial of service attack originating from the management network.

    Published: 18 Sept 2020
    9.8
    Critical

    CVE-2020-8158

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-8245

    Last Modified: 21 Nov 2024

    Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b leads to an HTML Injection attack against the SSL VPN web portal.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-8253

    Last Modified: 21 Nov 2024

    Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-8225

    Last Modified: 21 Nov 2024

    A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-11861

    Last Modified: 21 Nov 2024

    Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local privileges and gain root access on the system.

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-9084

    Last Modified: 21 Nov 2024

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

    Published: 18 Sept 2020
    2.3
    Low

    CVE-2020-16230

    Last Modified: 21 Nov 2024

    All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.

    Published: 18 Sept 2020
    6.8
    Medium

    CVE-2020-16247

    Last Modified: 4 Jun 2025

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

    Published: 18 Sept 2020
    9.3
    Critical

    CVE-2020-15181

    Last Modified: 21 Nov 2024

    The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-16200

    Last Modified: 4 Jun 2025

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

    Published: 18 Sept 2020
    5
    Medium

    CVE-2020-16198

    Last Modified: 4 Jun 2025

    When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.

    Published: 18 Sept 2020
    3.5
    Low

    CVE-2020-14525

    Last Modified: 4 Jun 2025

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.

    Published: 18 Sept 2020
    3.4
    Low

    CVE-2020-14506

    Last Modified: 4 Jun 2025

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-3979

    Last Modified: 21 Nov 2024

    InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker to plant a malicious library which could result in code execution with the security scope of the installer.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-25766

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.

    Published: 18 Sept 2020
    6.8
    Medium

    CVE-2020-15189

    Last Modified: 21 Nov 2024

    SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This vulnerability is caused by insecure configuration in elFinder. This is fixed in version 3.0.2.328.

    Published: 18 Sept 2020
    4.9
    Medium

    CVE-2020-14021

    Last Modified: 21 Nov 2024

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can be made to read any file on the Operating System, usually with NT AUTHORITY\SYSTEM privileges.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-14029

    Last Modified: 21 Nov 2024

    An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the application to an XML External Entity attack that can be used to perform SSRF or read arbitrary local files.

    Published: 18 Sept 2020
    10
    Critical

    CVE-2020-15188

    Last Modified: 21 Nov 2024

    SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any restrictions. This was fixed in 3.0.2.328.

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-24623

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft Hyper-V (VHD).

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0365

    Last Modified: 21 Nov 2024

    In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137346580

    Published: 18 Sept 2020
    4.4
    Medium

    CVE-2020-0349

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188779

    Published: 18 Sept 2020
    4.9
    Medium

    CVE-2020-0348

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188582

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0331

    Last Modified: 21 Nov 2024

    In Settings, there is a possible permissions bypass. This could lead to local information disclosure of the device's IMEI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147309310

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0327

    Last Modified: 21 Nov 2024

    In core networking, there is a missing permission check. This could lead to local information disclosure of app network usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129151407

    Published: 18 Sept 2020
    4.4
    Medium

    CVE-2020-0325

    Last Modified: 21 Nov 2024

    In NFC, there is a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145079309

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0316

    Last Modified: 21 Nov 2024

    In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934919

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0315

    Last Modified: 21 Nov 2024

    In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155642026

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0313

    Last Modified: 21 Nov 2024

    In NotificationManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154917989

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0311

    Last Modified: 21 Nov 2024

    In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153878642

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0310

    Last Modified: 21 Nov 2024

    In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356468

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0307

    Last Modified: 21 Nov 2024

    In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645867

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0304

    Last Modified: 21 Nov 2024

    In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645695

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0302

    Last Modified: 21 Nov 2024

    In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151646375

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-0300

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0295

    Last Modified: 21 Nov 2024

    In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155650969

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0294

    Last Modified: 21 Nov 2024

    In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154915372

    Published: 18 Sept 2020
    4.4
    Medium

    CVE-2020-0292

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-110107252

    Published: 18 Sept 2020
    4.4
    Medium

    CVE-2020-0291

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges and a compromised Firmware needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146032016

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-0286

    Last Modified: 21 Nov 2024

    In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150214479

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0285

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253479

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-5976

    Last Modified: 21 Nov 2024

    NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0284

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253784

    Published: 18 Sept 2020
    4.5
    Medium

    CVE-2020-0282

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction are needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144506224

    Published: 18 Sept 2020
    4.5
    Medium

    CVE-2020-0281

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137857778

    Published: 18 Sept 2020