CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2020-26159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Sept 2020
    6.5
    Medium

    CVE-2020-26541

    Last Modified: 21 Nov 2024

    The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

    Published: 15 Sept 2020
    5.6
    Medium

    CVE-2020-14390

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.

    Published: 15 Sept 2020
    7.5
    High

    CVE-2020-8251

    Last Modified: 30 Apr 2025

    Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.

    Published: 15 Sept 2020
    7.2
    High

    CVE-2020-13298

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure.

    Published: 14 Sept 2020
    3.5
    Low

    CVE-2020-13305

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not invalidating project invitation link upon removing a user from a project.

    Published: 14 Sept 2020
    5.4
    Medium

    CVE-2020-13309

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.

    Published: 14 Sept 2020
    6.5
    Medium

    CVE-2020-13310

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial of service.

    Published: 14 Sept 2020
    3.7
    Low

    CVE-2020-13315

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

    Published: 14 Sept 2020
    3.7
    Low

    CVE-2020-13306

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.

    Published: 14 Sept 2020
    5.5
    Medium

    CVE-2020-13301

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

    Published: 14 Sept 2020
    3.8
    Low

    CVE-2020-13302

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Under certain conditions GitLab was not properly revoking user sessions and allowed a malicious user to access a user account with an old password.

    Published: 14 Sept 2020
    3.8
    Low

    CVE-2020-13297

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. When 2 factor authentication was enabled for groups, a malicious user could bypass that restriction by sending a specific query to the API endpoint.

    Published: 14 Sept 2020
    3.8
    Low

    CVE-2020-13304

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

    Published: 14 Sept 2020
    7.5
    High

    CVE-2020-15590

    Last Modified: 21 Nov 2024

    A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch & associated iptables firewall is designed to protect you while using the Internet. When the kill switch is configured to block all inbound and outbound network traffic, privileged applications can continue sending & receiving network traffic if net.ipv4.ip_forward has been enabled in the system kernel parameters. For example, a Docker container running on a host with the VPN turned off, and the kill switch turned on, can continue using the internet, leaking the host IP (CWE 200). In PIA 2.4.0+, policy-based routing is enabled by default and is used to direct all forwarded packets to the VPN interface automatically.

    Published: 14 Sept 2020
    7.5
    High

    CVE-2020-11881

    Last Modified: 21 Nov 2024

    An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SUP-12964.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2020-10227

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.

    Published: 14 Sept 2020
    8.8
    High

    CVE-2020-10228

    Last Modified: 21 Nov 2024

    A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.

    Published: 14 Sept 2020
    8.8
    High

    CVE-2020-10229

    Last Modified: 21 Nov 2024

    A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.

    Published: 14 Sept 2020
    3.7
    Low

    CVE-2020-13314

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.

    Published: 14 Sept 2020
    4.3
    Medium

    CVE-2020-13311

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

    Published: 14 Sept 2020
    6.5
    Medium

    CVE-2020-13312

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab OAuth endpoint was vulnerable to brute-force attacks through a specific parameter.

    Published: 14 Sept 2020
    4.3
    Medium

    CVE-2020-13313

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.

    Published: 14 Sept 2020
    6.5
    Medium

    CVE-2020-13317

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.

    Published: 14 Sept 2020
    4.4
    Medium

    CVE-2019-14761

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take control over the Note application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    4.4
    Medium

    CVE-2019-14760

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker to take control over the Recorder application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    4.4
    Medium

    CVE-2019-14759

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Radio application. At a bare minimum, this allows an attacker to take control over the Radio application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2019-14758

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2019-14757

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    6.4
    Medium

    CVE-2020-13318

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.0.12, 13.1.10, 13.2.8 and 13.3.4. GitLabs EKS integration was vulnerable to a cross-account assume role attack.

    Published: 14 Sept 2020
    6.5
    Medium

    CVE-2020-13284

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. API Authorization Using Outdated CI Job Token

    Published: 14 Sept 2020
    5.4
    Medium

    CVE-2020-13289

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. In certain cases an invalid username could be accepted when 2FA is activated.

    Published: 14 Sept 2020
    4.3
    Medium

    CVE-2020-13287

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Project reporters and above could see confidential EPIC attached to confidential issues

    Published: 14 Sept 2020
    5.4
    Medium

    CVE-2020-13316

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

    Published: 14 Sept 2020
    8.1
    High

    CVE-2020-13299

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session.

    Published: 14 Sept 2020
    8
    High

    CVE-2020-13300

    Last Modified: 21 Nov 2024

    GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2019-14756

    Last Modified: 21 Nov 2024

    An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.

    Published: 14 Sept 2020
    7.6
    High

    CVE-2020-24457

    Last Modified: 21 Nov 2024

    Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

    Published: 14 Sept 2020
    9.8
    Critical

    CVE-2020-25573

    Last Modified: 21 Nov 2024

    An issue was discovered in the linked-hash-map crate before 0.5.3 for Rust. It creates an uninitialized NonNull pointer, which violates a non-null constraint.

    Published: 14 Sept 2020
    7.5
    High

    CVE-2020-25574

    Last Modified: 21 Nov 2024

    An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in denial of service (e.g., an infinite loop).

    Published: 14 Sept 2020
    9.8
    Critical

    CVE-2020-25576

    Last Modified: 19 Aug 2026

    An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.

    Published: 14 Sept 2020
    9.8
    Critical

    CVE-2020-25575

    Last Modified: 21 Nov 2024

    An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: This may overlap CVE-2019-25010

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2020-21845

    Last Modified: 21 Nov 2024

    Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'

    Published: 14 Sept 2020
    5.4
    Medium

    CVE-2020-25380

    Last Modified: 21 Nov 2024

    Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that will be stored and executed.

    Published: 14 Sept 2020
    8.8
    High

    CVE-2020-25379

    Last Modified: 21 Nov 2024

    Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2020-25378

    Last Modified: 21 Nov 2024

    Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.

    Published: 14 Sept 2020
    6.1
    Medium

    CVE-2020-22158

    Last Modified: 21 Nov 2024

    MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.

    Published: 14 Sept 2020
    5.4
    Medium

    CVE-2020-25375

    Last Modified: 21 Nov 2024

    Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.

    Published: 14 Sept 2020
    8.1
    High

    CVE-2020-8817

    Last Modified: 21 Nov 2024

    Dataiku DSS before 6.0.5 allows attackers write access to the project to modify the "Created by" metadata.

    Published: 14 Sept 2020
    9.8
    Critical

    CVE-2018-20432

    Last Modified: 21 Nov 2024

    D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.

    Published: 14 Sept 2020