CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2020-5621

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the device via unspecified vectors.

    Published: 28 Aug 2020
    4.4
    Medium

    CVE-2020-25639

    Last Modified: 21 Nov 2024

    A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.

    Published: 28 Aug 2020
    5.3
    Medium

    CVE-2021-20333

    Last Modified: 21 Nov 2024

    Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.

    Published: 28 Aug 2020
    4.3
    Medium

    CVE-2020-10517

    Last Modified: 21 Nov 2024

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in versions 2.21.6, 2.20.15, and 2.19.21. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 27 Aug 2020
    8.8
    High

    CVE-2020-10518

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and was fixed in 2.21.6, 2.20.15, and 2.19.21. The underlying issues contributing to this vulnerability were identified both internally and through the GitHub Security Bug Bounty program.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-24715

    Last Modified: 21 Nov 2024

    The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-24714

    Last Modified: 21 Nov 2024

    The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.

    Published: 27 Aug 2020
    7.2
    High

    CVE-2020-8602

    Last Modified: 21 Nov 2024

    A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution.

    Published: 27 Aug 2020
    8.1
    High

    CVE-2020-15605

    Last Modified: 21 Nov 2024

    If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.

    Published: 27 Aug 2020
    8.1
    High

    CVE-2020-15601

    Last Modified: 21 Nov 2024

    If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.

    Published: 27 Aug 2020
    6.5
    Medium

    CVE-2020-24618

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack versions before 2020.3.4313, 2020.2.11008, 2020.1.11011, 2019.1.65514, 2019.2.65515, and 2019.3.65516, an attacker can retrieve an issue description without appropriate access.

    Published: 27 Aug 2020
    5.3
    Medium

    CVE-2020-5383

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart.

    Published: 27 Aug 2020
    7.8
    High

    CVE-2020-24716

    Last Modified: 21 Nov 2024

    OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.

    Published: 27 Aug 2020
    7.8
    High

    CVE-2020-24717

    Last Modified: 21 Nov 2024

    OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-24203

    Last Modified: 21 Nov 2024

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-24202

    Last Modified: 21 Nov 2024

    File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

    Published: 27 Aug 2020
    7.2
    High

    CVE-2020-24196

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload in Vehicle Image Upload in Online Bike Rental v1.0 allows authenticated admin to conduct remote code execution.

    Published: 27 Aug 2020
    8.6
    High

    CVE-2020-3517

    Last Modified: 21 Nov 2024

    A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cause process crashes, which could result in a denial of service (DoS) condition on an affected device. The attack vector is configuration dependent and could be remote or adjacent. For more information about the attack vector, see the Details section of this advisory. The vulnerability is due to insufficient error handling when the affected software parses Cisco Fabric Services messages. An attacker could exploit this vulnerability by sending malicious Cisco Fabric Services messages to an affected device. A successful exploit could allow the attacker to cause a reload of an affected device, which could result in a DoS condition.

    Published: 27 Aug 2020
    7.5
    High

    CVE-2020-3338

    Last Modified: 21 Nov 2024

    A vulnerability in the Protocol Independent Multicast (PIM) feature for IPv6 networks (PIM6) of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper error handling when processing inbound PIM6 packets. An attacker could exploit this vulnerability by sending multiple crafted PIM6 packets to an affected device. A successful exploit could allow the attacker to cause the PIM6 application to leak system memory. Over time, this memory leak could cause the PIM6 application to stop processing legitimate PIM6 traffic, leading to a DoS condition on the affected device.

    Published: 27 Aug 2020
    7.8
    High

    CVE-2020-3394

    Last Modified: 21 Nov 2024

    A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to issue the enable command and get full administrative privileges. To exploit this vulnerability, the attacker would need to have valid credentials for the affected device. The vulnerability is due to a logic error in the implementation of the enable command. An attacker could exploit this vulnerability by logging in to the device and issuing the enable command. A successful exploit could allow the attacker to gain full administrative privileges without using the enable password. Note: The Enable Secret feature is disabled by default.

    Published: 27 Aug 2020
    8.6
    High

    CVE-2020-3397

    Last Modified: 21 Nov 2024

    A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incomplete input validation of a specific type of BGP MVPN update message. An attacker could exploit this vulnerability by sending this specific, valid BGP MVPN update message to a targeted device. A successful exploit could allow the attacker to cause one of the BGP-related routing applications to restart multiple times, leading to a system-level restart. Note: The Cisco implementation of BGP accepts incoming BGP traffic from only explicitly configured peers. To exploit this vulnerability, an attacker must send a specific BGP MVPN update message over an established TCP connection that appears to come from a trusted BGP peer. To do so, the attacker must obtain information about the BGP peers in the trusted network of the affected system.

    Published: 27 Aug 2020
    8.6
    High

    CVE-2020-3398

    Last Modified: 21 Nov 2024

    A vulnerability in the Border Gateway Protocol (BGP) Multicast VPN (MVPN) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a BGP session to repeatedly reset, causing a partial denial of service (DoS) condition due to the BGP session being down. The vulnerability is due to incorrect parsing of a specific type of BGP MVPN update message. An attacker could exploit this vulnerability by sending this BGP MVPN update message to a targeted device. A successful exploit could allow the attacker to cause the BGP peer connections to reset, which could lead to BGP route instability and impact traffic. The incoming BGP MVPN update message is valid but is parsed incorrectly by the NX-OS device, which could send a corrupted BGP update to the configured BGP peer. Note: The Cisco implementation of BGP accepts incoming BGP traffic from only explicitly configured peers. To exploit this vulnerability, an attacker must send a specific BGP MVPN update message over an established TCP connection that appears to come from a trusted BGP peer. To do so, the attacker must obtain information about the BGP peers in the trusted network of the affected system.

    Published: 27 Aug 2020
    8.8
    High

    CVE-2020-3415

    Last Modified: 21 Nov 2024

    A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to a Layer 2-adjacent affected device. A successful exploit could allow the attacker to execute arbitrary code with administrative privileges or cause the Cisco Discovery Protocol process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition. Note: Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). Exploitation of this vulnerability also requires jumbo frames to be enabled on the interface that receives the crafted Cisco Discovery Protocol packets on the affected device.

    Published: 27 Aug 2020
    7.2
    High

    CVE-2020-3454

    Last Modified: 21 Nov 2024

    A vulnerability in the Call Home feature of Cisco NX-OS Software could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges on the underlying operating system (OS). The vulnerability is due to insufficient input validation of specific Call Home configuration parameters when the software is configured for transport method HTTP. An attacker could exploit this vulnerability by modifying parameters within the Call Home configuration on an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying OS.

    Published: 27 Aug 2020
    3.3
    Low

    CVE-2020-3504

    Last Modified: 21 Nov 2024

    A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.

    Published: 27 Aug 2020
    3.5
    Low

    CVE-2020-16142

    Last Modified: 21 Nov 2024

    On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.

    Published: 27 Aug 2020
    5.4
    Medium

    CVE-2020-23576

    Last Modified: 21 Nov 2024

    Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-24390

    Last Modified: 21 Nov 2024

    eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.

    Published: 27 Aug 2020
    5.4
    Medium

    CVE-2020-23983

    Last Modified: 21 Nov 2024

    Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.

    Published: 27 Aug 2020
    5.4
    Medium

    CVE-2020-23984

    Last Modified: 21 Nov 2024

    Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-23982

    Last Modified: 21 Nov 2024

    DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-23981

    Last Modified: 21 Nov 2024

    13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-23979

    Last Modified: 21 Nov 2024

    13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-23978

    Last Modified: 21 Nov 2024

    SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-23977

    Last Modified: 21 Nov 2024

    KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-23976

    Last Modified: 21 Nov 2024

    Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-23975

    Last Modified: 21 Nov 2024

    Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.

    Published: 27 Aug 2020
    5.4
    Medium

    CVE-2020-23974

    Last Modified: 21 Nov 2024

    Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-23973

    Last Modified: 21 Nov 2024

    KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.

    Published: 27 Aug 2020
    7.5
    High

    CVE-2020-23972

    Last Modified: 21 Nov 2024

    In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

    Published: 27 Aug 2020
    6.5
    Medium

    CVE-2020-14371

    Last Modified: 21 Nov 2024

    A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.

    Published: 27 Aug 2020
    9.8
    Critical

    CVE-2020-23980

    Last Modified: 21 Nov 2024

    DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

    Published: 27 Aug 2020
    7.2
    High

    CVE-2020-4603

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 184880.

    Published: 27 Aug 2020
    6.1
    Medium

    CVE-2020-4575

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server ND 8.5 and 9.0, and IBM WebSphere Virtual Enterprise 7.0 and 8.0 are vulnerable to cross-site scripting when High Availability Deployment Manager is configured.

    Published: 27 Aug 2020
    5.9
    Medium

    CVE-2020-4175

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174684.

    Published: 27 Aug 2020
    5.3
    Medium

    CVE-2020-4172

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 174408.

    Published: 27 Aug 2020
    4.3
    Medium

    CVE-2020-4171

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174407.

    Published: 27 Aug 2020
    7.5
    High

    CVE-2020-4169

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 174405.

    Published: 27 Aug 2020
    6.5
    Medium

    CVE-2020-4167

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenciation mechanisms. IBM X-Force ID: 174403.

    Published: 27 Aug 2020
    5.3
    Medium

    CVE-2020-4166

    Last Modified: 21 Nov 2024

    IBM Security Guardium Insights 2.0.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 174402.

    Published: 27 Aug 2020