CVE Feed

    Dashboard / CVE

    2.4
    Low

    CVE-2020-9083

    Last Modified: 21 Nov 2024

    HUAWEI Mate 20 smart phones with Versions earlier than 10.1.0.163(C00E160R3P8) have a denial of service (DoS) vulnerability. The attacker can enter a large amount of text on the phone. Due to insufficient verification of the parameter, successful exploitation can impact the service.

    Published: 3 Sept 2020
    5.5
    Medium

    CVE-2020-9235

    Last Modified: 21 Nov 2024

    Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3);Versions earlier than 10.1.0.212(C00E210R5P1);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C01E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R8P12);Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2) contain an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerability to obtain some information. This can lead to information leak.

    Published: 3 Sept 2020
    9.8
    Critical

    CVE-2020-24193

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.

    Published: 3 Sept 2020
    6.8
    Medium

    CVE-2020-9199

    Last Modified: 21 Nov 2024

    B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-25125

    Last Modified: 21 Nov 2024

    GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed version.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25115

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25116

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25117

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25118

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25119

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25120

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25121

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25122

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25123

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager.

    Published: 3 Sept 2020
    4.8
    Medium

    CVE-2020-25124

    Last Modified: 21 Nov 2024

    The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI.

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-11579

    Last Modified: 21 Nov 2024

    An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-23814

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-23811

    Last Modified: 21 Nov 2024

    xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25102

    Last Modified: 21 Nov 2024

    silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-24162

    Last Modified: 21 Nov 2024

    The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-24161

    Last Modified: 21 Nov 2024

    Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious code.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-24160

    Last Modified: 21 Nov 2024

    Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-24159

    Last Modified: 21 Nov 2024

    NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-24158

    Last Modified: 21 Nov 2024

    360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.

    Published: 3 Sept 2020
    9.8
    Critical

    CVE-2020-24876

    Last Modified: 21 Nov 2024

    Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2019-10679

    Last Modified: 21 Nov 2024

    Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-13972

    Last Modified: 21 Nov 2024

    Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScript returned from the external server is executed in the browser. This is related to CVE-2019-16951.

    Published: 3 Sept 2020
    5.5
    Medium

    CVE-2020-24385

    Last Modified: 21 Nov 2024

    In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compat/linux/linux_emul.h is not getting initialized and returns NULL from em_find().

    Published: 3 Sept 2020
    5.5
    Medium

    CVE-2020-24863

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.

    Published: 3 Sept 2020
    —
    Unknown

    CVE-2020-16149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requestor. Notes: none

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-25068

    Last Modified: 21 Nov 2024

    Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.

    Published: 3 Sept 2020
    7.2
    High

    CVE-2020-25042

    Last Modified: 21 Nov 2024

    An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.

    Published: 3 Sept 2020
    5.4
    Medium

    CVE-2020-25104

    Last Modified: 21 Nov 2024

    eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

    Published: 3 Sept 2020
    9.8
    Critical

    CVE-2020-25105

    Last Modified: 21 Nov 2024

    eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).

    Published: 3 Sept 2020
    7.2
    High

    CVE-2020-24948

    Last Modified: 21 Nov 2024

    The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

    Published: 3 Sept 2020
    6.8
    Medium

    CVE-2020-7382

    Last Modified: 21 Nov 2024

    Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6.6.40.

    Published: 3 Sept 2020
    5.8
    Medium

    CVE-2020-7381

    Last Modified: 21 Nov 2024

    In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.

    Published: 3 Sept 2020
    7.2
    High

    CVE-2020-4638

    Last Modified: 21 Nov 2024

    IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.

    Published: 3 Sept 2020
    6.5
    Medium

    CVE-2020-4337

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.4.1.0 through 2018.4.1.12 could allow an attacker to launch phishing attacks by tricking the server to generate user registration emails that contain malicious URLs. IBM X-Force ID: 177933.

    Published: 3 Sept 2020
    8.8
    High

    CVE-2020-24949

    Last Modified: 21 Nov 2024

    Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-12058

    Last Modified: 21 Nov 2024

    Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.

    Published: 3 Sept 2020
    7.1
    High

    CVE-2020-7729

    Last Modified: 21 Nov 2024

    The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25086

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25087

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25088

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25089

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25090

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25091

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25092

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-25093

    Last Modified: 21 Nov 2024

    Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.

    Published: 3 Sept 2020