CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-13828

    Last Modified: 21 Nov 2024

    Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.

    Published: 31 Aug 2020
    6.7
    Medium

    CVE-2020-5419

    Last Modified: 2 Apr 2025

    RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

    Published: 31 Aug 2020
    6.5
    Medium

    CVE-2020-13595

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of completed BLE packets and triggers a reachable assertion on the host stack when receiving a packet with an MIC failure. An attacker within radio range can silently trigger the assertion (which disables the target's BLE stack) by sending a crafted sequence of BLE packets.

    Published: 31 Aug 2020
    6.5
    Medium

    CVE-2020-13594

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.2 and earlier (for ESP32 devices) does not properly restrict the channel map field of the connection request packet on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.

    Published: 31 Aug 2020
    8.8
    High

    CVE-2020-13593

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Layer encryption setup is performed earlier. An attacker in radio range can achieve arbitrary read/write access to protected GATT service data, cause a denial of service, or possibly control a device's function by establishing an encrypted session with an unauthenticated Long Term Key (LTK).

    Published: 31 Aug 2020
    5.4
    Medium

    CVE-2020-12646

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-12645

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

    Published: 31 Aug 2020
    5
    Medium

    CVE-2020-12644

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

    Published: 31 Aug 2020
    4.3
    Medium

    CVE-2020-12643

    Last Modified: 21 Nov 2024

    OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.

    Published: 31 Aug 2020
    7.8
    High

    CVE-2020-11618

    Last Modified: 21 Nov 2024

    THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.

    Published: 31 Aug 2020
    5.9
    Medium

    CVE-2020-11617

    Last Modified: 21 Nov 2024

    The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to modify the data delivered to the client.

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-13655

    Last Modified: 21 Nov 2024

    An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-24786

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

    Published: 31 Aug 2020
    9.8
    Critical

    CVE-2020-24115

    Last Modified: 21 Nov 2024

    In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

    Published: 31 Aug 2020
    5.5
    Medium

    CVE-2020-4492

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale V5.0.0.0 through V5.0.4.3 and V4.2.0.0 through V4.2.3.21 could allow a local attacker to cause a denial of service crashing the kernel by sending a subset of ioctls on the device with invalid arguments. IBM X-Force ID: 181992.

    Published: 31 Aug 2020
    5.4
    Medium

    CVE-2020-15020

    Last Modified: 21 Nov 2024

    An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-25033

    Last Modified: 21 Nov 2024

    The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.

    Published: 31 Aug 2020
    7.8
    High

    CVE-2020-25031

    Last Modified: 21 Nov 2024

    checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-14380

    Last Modified: 21 Nov 2024

    An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.

    Published: 31 Aug 2020
    7.1
    High

    CVE-2020-14365

    Last Modified: 21 Nov 2024

    A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious packages being installed on the system and arbitrary code executed via package installation scripts. The highest threat from this vulnerability is to integrity and system availability.

    Published: 31 Aug 2020
    7.5
    High

    CVE-2020-25032

    Last Modified: 21 Nov 2024

    An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

    Published: 31 Aug 2020
    6.1
    Medium

    CVE-2020-24104

    Last Modified: 21 Nov 2024

    XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.

    Published: 30 Aug 2020
    8.1
    High

    CVE-2020-8097

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tamper with the product's security settings. This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.18.261. This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.18.261. Bitdefender Endpoint Security SDK versions prior to 6.6.18.261.

    Published: 30 Aug 2020
    6.1
    Medium

    CVE-2020-24223

    Last Modified: 21 Nov 2024

    Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.

    Published: 30 Aug 2020
    6.1
    Medium

    CVE-2020-24917

    Last Modified: 21 Nov 2024

    osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.

    Published: 30 Aug 2020
    7.2
    High

    CVE-2020-7712

    Last Modified: 21 Nov 2024

    This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

    Published: 30 Aug 2020
    6.5
    Medium

    CVE-2020-8244

    Last Modified: 21 Nov 2024

    A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.

    Published: 30 Aug 2020
    8.8
    High

    CVE-2020-24972

    Last Modified: 21 Nov 2024

    The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.

    Published: 29 Aug 2020
    8.9
    High

    CVE-2020-24897

    Last Modified: 21 Nov 2024

    The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.

    Published: 29 Aug 2020
    7.6
    High

    CVE-2020-24898

    Last Modified: 21 Nov 2024

    The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).

    Published: 29 Aug 2020
    5.3
    Medium

    CVE-2020-24928

    Last Modified: 21 Nov 2024

    managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to obtain sensitive Discord user information.

    Published: 29 Aug 2020
    9.8
    Critical

    CVE-2020-25020

    Last Modified: 5 May 2025

    MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

    Published: 29 Aug 2020
    7.5
    High

    CVE-2020-25019

    Last Modified: 17 Nov 2025

    jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

    Published: 29 Aug 2020
    8.6
    High

    CVE-2020-3566

    Last Modified: 28 Oct 2025

    A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting in instability of other processes. These processes may include, but are not limited to, interior and exterior routing protocols. Cisco will release software updates that address this vulnerability.

    Published: 29 Aug 2020
    9.1
    Critical

    CVE-2020-25016

    Last Modified: 21 Nov 2024

    A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.

    Published: 29 Aug 2020
    7.6
    High

    CVE-2020-15159

    Last Modified: 21 Nov 2024

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file.The affected components are ThemeFilesController.php and UploaderFilesController.php. This is fixed in version 4.3.7.

    Published: 28 Aug 2020
    7.3
    High

    CVE-2020-15155

    Last Modified: 21 Nov 2024

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.

    Published: 28 Aug 2020
    7.3
    High

    CVE-2020-15154

    Last Modified: 21 Nov 2024

    baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7.

    Published: 28 Aug 2020
    6.5
    Medium

    CVE-2012-4818

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system.

    Published: 28 Aug 2020
    9.3
    Critical

    CVE-2020-15165

    Last Modified: 21 Nov 2024

    Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.

    Published: 28 Aug 2020
    10
    Critical

    CVE-2020-15164

    Last Modified: 21 Nov 2024

    in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by MediaWiki. This affects all users on any wiki using this extension. Since version 1.1, comments by users whose usernames would be trimmed on MediaWiki are ignored when searching for the verification code.

    Published: 28 Aug 2020
    4.3
    Medium

    CVE-2020-16610

    Last Modified: 21 Nov 2024

    Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenticated admin user to a malicious web page, any accounts can be deleted without admin user's intention.

    Published: 28 Aug 2020
    7.5
    High

    CVE-2020-9298

    Last Modified: 21 Nov 2024

    The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.

    Published: 28 Aug 2020
    3.3
    Low

    CVE-2020-4591

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Server 8.1.0.000 through 8.1.10.000 could disclose sensitive information in nondefault settings due to occasionally not encrypting the second chunk of an object in an encrypted container pool. IBM X-Force ID: 184746.

    Published: 28 Aug 2020
    7.5
    High

    CVE-2020-4559

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect 7.1 and 8.1 could allow an attacker to cause a denial of service due ti improper validation of user-supplied input. IBM X-Force ID: 183613.

    Published: 28 Aug 2020
    4.3
    Medium

    CVE-2019-4579

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.

    Published: 28 Aug 2020
    4.3
    Medium

    CVE-2019-4533

    Last Modified: 21 Nov 2024

    IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.

    Published: 28 Aug 2020
    6.1
    Medium

    CVE-2020-5625

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in XooNIps 3.48 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

    Published: 28 Aug 2020
    6.1
    Medium

    CVE-2020-5623

    Last Modified: 21 Nov 2024

    NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 28 Aug 2020
    9.8
    Critical

    CVE-2020-5624

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Aug 2020