CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2020-5420

    Last Modified: 21 Nov 2024

    Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters.

    Published: 3 Sept 2020
    4.3
    Medium

    CVE-2020-5418

    Last Modified: 21 Nov 2024

    Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-29651

    Last Modified: 3 Nov 2025

    A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

    Published: 3 Sept 2020
    6.1
    Medium

    CVE-2020-10746

    Last Modified: 21 Nov 2024

    A flaw was found in Infinispan (org.infinispan:infinispan-server-runtime) version 10, where it permits local access to controls via both REST and HotRod APIs. This flaw allows a user authenticated to the local machine to perform all operations on the caches, including the creation, update, deletion, and shutdown of the entire server.

    Published: 3 Sept 2020
    4.4
    Medium

    CVE-2020-14342

    Last Modified: 21 Nov 2024

    It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-14384

    Last Modified: 21 Nov 2024

    A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

    Published: 3 Sept 2020
    6.7
    Medium

    CVE-2020-14386

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

    Published: 3 Sept 2020
    7.8
    High

    CVE-2020-14382

    Last Modified: 21 Nov 2024

    A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement "intervals = malloc(first_backup * sizeof(*intervals));"). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.

    Published: 3 Sept 2020
    7.5
    High

    CVE-2020-5386

    Last Modified: 21 Nov 2024

    Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.

    Published: 2 Sept 2020
    6.8
    Medium

    CVE-2020-5379

    Last Modified: 21 Nov 2024

    Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

    Published: 2 Sept 2020
    6.8
    Medium

    CVE-2020-5378

    Last Modified: 21 Nov 2024

    Dell G7 17 7790 BIOS versions prior to 1.13.2 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

    Published: 2 Sept 2020
    6.8
    Medium

    CVE-2020-5376

    Last Modified: 21 Nov 2024

    Dell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

    Published: 2 Sept 2020
    8.8
    High

    CVE-2020-5369

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authenticated malicious user may exploit this vulnerability by using SyncIQ to gain unauthorized access to system management files.

    Published: 2 Sept 2020
    7.1
    High

    CVE-2020-25044

    Last Modified: 21 Nov 2024

    Kaspersky Virus Removal Tool (KVRT) prior to 15.0.23.0 was vulnerable to arbitrary file corruption that could provide an attacker with the opportunity to eliminate content of any file in the system.

    Published: 2 Sept 2020
    7.1
    High

    CVE-2020-25043

    Last Modified: 21 Nov 2024

    The installer of Kaspersky VPN Secure Connection prior to 5.0 was vulnerable to arbitrary file deletion that could allow an attacker to delete any file in the system.

    Published: 2 Sept 2020
    7.8
    High

    CVE-2020-25045

    Last Modified: 21 Nov 2024

    Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

    Published: 2 Sept 2020
    7.5
    High

    CVE-2020-5779

    Last Modified: 21 Nov 2024

    A flaw in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) relates to invalid parameter handling when calling strcpy_s() with an invalid parameter (i.e., a long src string parameter) as a part of processing a type 4 message sent to default TCP RequestPort 10200. It's been observed that ttmd.exe terminates as a result.

    Published: 2 Sept 2020
    7.5
    High

    CVE-2020-5778

    Last Modified: 21 Nov 2024

    A flaw exists in Trading Technologies Messaging 7.1.28.3 (ttmd.exe) due to improper validation of user-supplied data when processing a type 8 message sent to default TCP RequestPort 10200. An unauthenticated, remote attacker can exploit this issue, via a specially crafted message, to terminate ttmd.exe.

    Published: 2 Sept 2020
    5.4
    Medium

    CVE-2020-8576

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or disclosure of sensitive information.

    Published: 2 Sept 2020
    7.8
    High

    CVE-2020-7830

    Last Modified: 21 Nov 2024

    RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths. This issue affects: RAONWIZ RAON KUpload 2018.0.2.50 versions and earlier.

    Published: 2 Sept 2020
    9.8
    Critical

    CVE-2020-4693

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 7.1.0.000 through 7.1.10 and 8.1.0.000 through 8.1.9 may allow an attacker to execute arbitrary code on the system, caused by improper validation of data prior to export. IBM X-Force ID: 186782.

    Published: 2 Sept 2020
    5.4
    Medium

    CVE-2020-4546

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183314.

    Published: 2 Sept 2020
    5.4
    Medium

    CVE-2020-4522

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182397.

    Published: 2 Sept 2020
    5.4
    Medium

    CVE-2020-4445

    Last Modified: 21 Nov 2024

    IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 181122.

    Published: 2 Sept 2020
    8.2
    High

    CVE-2020-15167

    Last Modified: 21 Nov 2024

    In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete details. A fix is ready and will be released as Miller 5.9.1.

    Published: 2 Sept 2020
    8
    High

    CVE-2020-15094

    Last Modified: 21 Nov 2024

    In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

    Published: 2 Sept 2020
    8.8
    High

    CVE-2020-14209

    Last Modified: 21 Nov 2024

    Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be executed as PHP code to defeat the .noexe protection mechanism).

    Published: 2 Sept 2020
    9.8
    Critical

    CVE-2020-13802

    Last Modified: 21 Nov 2024

    Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

    Published: 2 Sept 2020
    6.1
    Medium

    CVE-2020-12621

    Last Modified: 21 Nov 2024

    The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component.

    Published: 2 Sept 2020
    4.3
    Medium

    CVE-2020-25025

    Last Modified: 21 Nov 2024

    The l10nmgr (aka Localization Manager) extension before 7.4.0, 8.x before 8.7.0, and 9.x before 9.2.0 for TYPO3 allows Information Disclosure (translatable fields).

    Published: 2 Sept 2020
    4.3
    Medium

    CVE-2020-25026

    Last Modified: 21 Nov 2024

    The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.

    Published: 2 Sept 2020
    8.8
    High

    CVE-2020-24028

    Last Modified: 14 Oct 2025

    ForLogic Qualiex v1 and v3 allows any authenticated customer to achieve privilege escalation via user creations, password changes, or user permission updates. NOTE: as of 2025-10-14, the Supplier's perspective is that this "does not allow administrative privilege gain. Authorization is enforced server-side, restricting actions to the user’s own permission scope."

    Published: 2 Sept 2020
    9.8
    Critical

    CVE-2020-24029

    Last Modified: 14 Oct 2025

    Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "corrected in all maintained versions. Password reset requests are validated against registered user emails and require a valid, short-lived token."

    Published: 2 Sept 2020
    9.8
    Critical

    CVE-2020-24030

    Last Modified: 14 Oct 2025

    ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this is "not exploitable in the current implementation. Tokens are properly expired, invalidated, and bound to session context. Attempts to alter the token payload to extend its validity do not affect server-side validation."

    Published: 2 Sept 2020
    7.1
    High

    CVE-2020-23830

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.

    Published: 2 Sept 2020
    7.5
    High

    CVE-2020-25078

    Last Modified: 7 Nov 2025

    An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

    Published: 2 Sept 2020
    8.8
    High

    CVE-2020-25079

    Last Modified: 7 Nov 2025

    An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

    Published: 2 Sept 2020
    6.1
    Medium

    CVE-2020-24601

    Last Modified: 21 Nov 2024

    In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page

    Published: 2 Sept 2020
    6.1
    Medium

    CVE-2020-24604

    Last Modified: 21 Nov 2024

    A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp

    Published: 2 Sept 2020
    6.1
    Medium

    CVE-2020-24602

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in the Server Properties and Security Audit Viewer JSP page

    Published: 2 Sept 2020
    5.4
    Medium

    CVE-2020-17458

    Last Modified: 21 Nov 2024

    A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field.

    Published: 2 Sept 2020
    8.1
    High

    CVE-2020-16602

    Last Modified: 21 Nov 2024

    Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step.

    Published: 2 Sept 2020
    9.8
    Critical

    CVE-2020-24355

    Last Modified: 21 Nov 2024

    Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows regular and other users to create new users with elevated privileges. This is done by changing "FirstIndex" field in JSON that is POST-ed during account creation. Similar may also be possible with account deletion.

    Published: 2 Sept 2020
    5.5
    Medium

    CVE-2020-14373

    Last Modified: 21 Nov 2024

    A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.

    Published: 2 Sept 2020
    7.5
    High

    CVE-2020-5622

    Last Modified: 21 Nov 2024

    Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to cause a denial of service which may result in not being able to add newly detected attack source IP addresses as blocking targets for about 10 minutes via a specially crafted request.

    Published: 2 Sept 2020
    5.3
    Medium

    CVE-2020-25073

    Last Modified: 21 Nov 2024

    FreedomBox through 20.13 allows remote attackers to obtain sensitive information from the /server-status page of the Apache HTTP Server, because a connection from the Tor onion service (or from PageKite) is considered a local connection. This affects both the freedombox and plinth packages of some Linux distributions, but only if the Apache mod_status module is enabled.

    Published: 2 Sept 2020
    5.5
    Medium

    CVE-2020-16150

    Last Modified: 21 Nov 2024

    A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.

    Published: 2 Sept 2020
    7.8
    High

    CVE-2020-24955

    Last Modified: 21 Nov 2024

    SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware.

    Published: 1 Sept 2020
    2.4
    Low

    CVE-2020-8341

    Last Modified: 21 Nov 2024

    In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in various versions of BIOS for some Lenovo ThinkPad systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.

    Published: 1 Sept 2020
    6.1
    Medium

    CVE-2020-8335

    Last Modified: 21 Nov 2024

    The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w, while the emergency-reset button is pressed which may allow for unauthorized access.

    Published: 1 Sept 2020