CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-24584

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-7720

    Last Modified: 21 Nov 2024

    The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

    Published: 1 Sept 2020
    7.5
    High

    CVE-2020-36325

    Last Modified: 21 Nov 2024

    An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-access bug. NOTE: the vendor reports that this only occurs when a programmer fails to follow the API specification

    Published: 1 Sept 2020
    9.8
    Critical

    CVE-2020-25057

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25059

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A service crash may occur because of incorrect input validation. The LG ID is LVE-SMP-200013 (July 2020).

    Published: 31 Aug 2020
    7.8
    High

    CVE-2020-25060

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Local users can gain privileges because of LAF and SBL1 flaws. The LG ID is LVE-SMP-200015 (July 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25061

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25062

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25063

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. An application crash can occur because of incorrect application-level input validation. The LG ID is LVE-SMP-200018 (July 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25064

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Certain automated testing is mishandled. The LG ID is LVE-SMP-200019 (August 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25065

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 4.4, 5.0, 5.1, 6.0, 7.0, 7.1, 8.0, 8.1, 9.0, and 10 software. Key logging may occur because of an obsolete API. The LG ID is LVE-SMP-170010 (August 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25058

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).

    Published: 31 Aug 2020
    5.5
    Medium

    CVE-2020-25046

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2020-17602, SVE-2020-17603, SVE-2020-17604 (August 2020).

    Published: 31 Aug 2020
    5.5
    Medium

    CVE-2020-25047

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (released in China and India) software. The S Secure application does not enforce the intended password requirement for a locked application. The Samsung IDs are SVE-2020-16746, SVE-2020-16764 (August 2020).

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-25048

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25049

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25050

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The CMC service allows attackers to obtain sensitive information. The Samsung ID is SVE-2020-17288 (August 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25051

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppInfo. The Samsung ID is SVE-2020-17758 (August 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25052

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because indexes are mishandled. The Samsung ID is SVE-2020-17426 (August 2020).

    Published: 31 Aug 2020
    9.1
    Critical

    CVE-2020-25054

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2020-04-02 (Exynos modem chipsets). There is a heap-based buffer over-read in the Shannon baseband. The Samsung ID is SVE-2020-17239 (August 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25055

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25056

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) (Galaxy S20) software. Because HAL improperly checks versions, bootloading by the S.LSI NFC chipset is mishandled. The Samsung ID is SVE-2020-16169 (August 2020).

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-25053

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).

    Published: 31 Aug 2020
    8.8
    High

    CVE-2020-24354

    Last Modified: 21 Nov 2024

    Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-2075

    Last Modified: 21 Nov 2024

    Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.

    Published: 31 Aug 2020
    7.8
    High

    CVE-2020-7527

    Last Modified: 21 Nov 2024

    Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.

    Published: 31 Aug 2020
    8.8
    High

    CVE-2020-7526

    Last Modified: 21 Nov 2024

    Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-7525

    Last Modified: 21 Nov 2024

    Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-7524

    Last Modified: 21 Nov 2024

    Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.

    Published: 31 Aug 2020
    7.8
    High

    CVE-2020-7523

    Last Modified: 21 Nov 2024

    Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-7522

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-7521

    Last Modified: 21 Nov 2024

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-20628

    Last Modified: 21 Nov 2024

    controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.

    Published: 31 Aug 2020
    5.3
    Medium

    CVE-2020-20627

    Last Modified: 21 Nov 2024

    The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.

    Published: 31 Aug 2020
    5.4
    Medium

    CVE-2020-20626

    Last Modified: 21 Nov 2024

    lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-20625

    Last Modified: 21 Nov 2024

    Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.

    Published: 31 Aug 2020
    8.8
    High

    CVE-2020-24363

    Last Modified: 7 Nov 2025

    TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-13472

    Last Modified: 21 Nov 2024

    The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-15687

    Last Modified: 21 Nov 2024

    Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a corrupt state and Denial of Service (DoS) for previously assigned PCIe devices to the Service VM at runtime.

    Published: 31 Aug 2020
    6.8
    Medium

    CVE-2020-13471

    Last Modified: 21 Nov 2024

    Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-13470

    Last Modified: 21 Nov 2024

    Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data.

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-13469

    Last Modified: 21 Nov 2024

    The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-24699

    Last Modified: 21 Nov 2024

    The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.

    Published: 31 Aug 2020
    6.8
    Medium

    CVE-2020-13468

    Last Modified: 21 Nov 2024

    Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-17465

    Last Modified: 21 Nov 2024

    Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-13467

    Last Modified: 21 Nov 2024

    The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.

    Published: 31 Aug 2020
    6.8
    Medium

    CVE-2020-13466

    Last Modified: 21 Nov 2024

    STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.

    Published: 31 Aug 2020
    6.8
    Medium

    CVE-2020-13465

    Last Modified: 21 Nov 2024

    The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.

    Published: 31 Aug 2020
    4.2
    Medium

    CVE-2020-13464

    Last Modified: 21 Nov 2024

    The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.

    Published: 31 Aug 2020
    4.6
    Medium

    CVE-2020-13463

    Last Modified: 21 Nov 2024

    The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.

    Published: 31 Aug 2020