CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-6123

    Last Modified: 21 Nov 2024

    An exploitable sql injection vulnerability exists in the email parameter functionality of OS4Ed openSIS 7.3. The email parameter in the page EmailCheck.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    4.3
    Medium

    CVE-2020-14514

    Last Modified: 21 Nov 2024

    All trailer Power Line Communications are affected. PLC bus traffic can be sniffed reliably via an active antenna up to 6 feet away. Further distances are also possible, subject to environmental conditions and receiver improvements.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6122

    Last Modified: 21 Nov 2024

    SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The mn parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6121

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The ln parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6120

    Last Modified: 21 Nov 2024

    SQL injection vulnerability exists in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The fn parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-7669

    Last Modified: 21 Nov 2024

    This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-7666

    Last Modified: 21 Nov 2024

    This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-7665

    Last Modified: 21 Nov 2024

    This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6119

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The byear parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6118

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bmonth parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6117

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the CheckDuplicateStudent.php page of OS4Ed openSIS 7.3. The bday parameter in the page CheckDuplicateStudent.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 1 Sept 2020
    3.3
    Low

    CVE-2020-2249

    Last Modified: 21 Nov 2024

    Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

    Published: 1 Sept 2020
    4.3
    Medium

    CVE-2020-2251

    Last Modified: 21 Nov 2024

    Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 1 Sept 2020
    6.5
    Medium

    CVE-2020-2250

    Last Modified: 21 Nov 2024

    Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

    Published: 1 Sept 2020
    6.1
    Medium

    CVE-2020-2248

    Last Modified: 21 Nov 2024

    Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.

    Published: 1 Sept 2020
    6.5
    Medium

    CVE-2020-2247

    Last Modified: 21 Nov 2024

    Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 1 Sept 2020
    7.1
    High

    CVE-2020-2245

    Last Modified: 21 Nov 2024

    Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 1 Sept 2020
    5.4
    Medium

    CVE-2020-2246

    Last Modified: 21 Nov 2024

    Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents.

    Published: 1 Sept 2020
    5.4
    Medium

    CVE-2020-2244

    Last Modified: 21 Nov 2024

    Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.

    Published: 1 Sept 2020
    6.5
    Medium

    CVE-2020-2242

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.

    Published: 1 Sept 2020
    5.4
    Medium

    CVE-2020-2243

    Last Modified: 21 Nov 2024

    Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-2241

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-2240

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.

    Published: 1 Sept 2020
    5.4
    Medium

    CVE-2020-2238

    Last Modified: 21 Nov 2024

    Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

    Published: 1 Sept 2020
    4.3
    Medium

    CVE-2020-2239

    Last Modified: 21 Nov 2024

    Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-24554

    Last Modified: 21 Nov 2024

    The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6131

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassScheduleSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6130

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page MassDropSessionSet.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

    Published: 1 Sept 2020
    8.8
    High

    CVE-2020-6129

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exist in the course_period_id parameters used in OS4Ed openSIS 7.3 pages. The course_period_id parameter in the page CpSessionSet.php is vulnerable to SQL injection.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

    Published: 1 Sept 2020
    6.5
    Medium

    CVE-2018-12475

    Last Modified: 21 Nov 2024

    A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUSE Open Build Service allows authenticated users to generate HTTP request against internal networks and potentially downloading data that is exposed there. This issue affects: openSUSE Open Build Service .

    Published: 1 Sept 2020
    7.7
    High

    CVE-2020-8023

    Last Modified: 21 Nov 2024

    A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of Sale 11-SP3, SUSE Linux Enterprise Server 11-SECURITY, SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1, openSUSE Leap 15.2 allows local attackers to escalate privileges from user ldap to root. This issue affects: SUSE Enterprise Storage 5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Debuginfo 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Debuginfo 11-SP4 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Point of Sale 11-SP3 openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 11-SECURITY openldap2-client-openssl1 versions prior to 2.4.26-0.74.13.1. SUSE Linux Enterprise Server 11-SP4-LTSS openldap2 versions prior to 2.4.26-0.74.13.1,. SUSE Linux Enterprise Server 12-SP2-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP2-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-BCL openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP3-LTSS openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP4 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 12-SP5 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server 15-LTSS openldap2 versions prior to 2.4.46-9.31.1. SUSE Linux Enterprise Server for SAP 12-SP2 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 12-SP3 openldap2 versions prior to 2.4.41-18.71.2. SUSE Linux Enterprise Server for SAP 15 openldap2 versions prior to 2.4.46-9.31.1. SUSE OpenStack Cloud 7 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud 8 openldap2 versions prior to 2.4.41-18.71.2. SUSE OpenStack Cloud Crowbar 8 openldap2 versions prior to 2.4.41-18.71.2. openSUSE Leap 15.1 openldap2 versions prior to 2.4.46-lp151.10.12.1. openSUSE Leap 15.2 openldap2 versions prior to 2.4.46-lp152.14.3.1.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7725

    Last Modified: 21 Nov 2024

    All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7726

    Last Modified: 21 Nov 2024

    All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7727

    Last Modified: 21 Nov 2024

    All versions of package gedi are vulnerable to Prototype Pollution via the set function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7723

    Last Modified: 21 Nov 2024

    All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7724

    Last Modified: 21 Nov 2024

    All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7721

    Last Modified: 21 Nov 2024

    All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7722

    Last Modified: 21 Nov 2024

    All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7719

    Last Modified: 21 Nov 2024

    Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7717

    Last Modified: 21 Nov 2024

    All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7718

    Last Modified: 21 Nov 2024

    All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7714

    Last Modified: 21 Nov 2024

    All versions of package confucious are vulnerable to Prototype Pollution via the set function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7715

    Last Modified: 21 Nov 2024

    All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7716

    Last Modified: 21 Nov 2024

    All versions of package deeps are vulnerable to Prototype Pollution via the set function.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7713

    Last Modified: 21 Nov 2024

    All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.

    Published: 1 Sept 2020
    6.6
    Medium

    CVE-2020-12776

    Last Modified: 21 Nov 2024

    Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-14178

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

    Published: 1 Sept 2020
    9.6
    Critical

    CVE-2020-25067

    Last Modified: 21 Nov 2024

    NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.

    Published: 1 Sept 2020
    5.9
    Medium

    CVE-2020-13946

    Last Modified: 21 Nov 2024

    In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and perform unauthorised operations. Users should also be aware of CVE-2019-2684, a JRE vulnerability that enables this issue to be exploited remotely.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-24583

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectstatic management command.

    Published: 1 Sept 2020