CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2020-14042

    Last Modified: 21 Nov 2024

    ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Site Scripting (XSS) vulnerability was found in Codiad v1.7.8 and later. The vulnerability occurs because of improper sanitization of the folder's name $path variable in components/filemanager/class.filemanager.php. NOTE: the vendor states "Codiad is no longer under active maintenance by core contributors."

    Published: 25 Aug 2020
    6.1
    Medium

    CVE-2020-24609

    Last Modified: 21 Nov 2024

    TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via crafted payload.

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-24614

    Last Modified: 21 Nov 2024

    Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.

    Published: 25 Aug 2020
    9.8
    Critical

    CVE-2020-14524

    Last Modified: 21 Nov 2024

    Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

    Published: 25 Aug 2020
    7.5
    High

    CVE-2020-14522

    Last Modified: 21 Nov 2024

    Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource consumption, which may allow an attacker to cause a denial-of-service condition.

    Published: 25 Aug 2020
    8.1
    High

    CVE-2020-14512

    Last Modified: 21 Nov 2024

    GateManager versions prior to 9.2c, The affected product uses a weak hash type, which may allow an attacker to view user passwords.

    Published: 25 Aug 2020
    9.8
    Critical

    CVE-2020-14510

    Last Modified: 21 Nov 2024

    GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.

    Published: 25 Aug 2020
    8.1
    High

    CVE-2020-14508

    Last Modified: 21 Nov 2024

    GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.

    Published: 25 Aug 2020
    10
    Critical

    CVE-2020-14500

    Last Modified: 21 Nov 2024

    Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.

    Published: 25 Aug 2020
    5.5
    Medium

    CVE-2020-14385

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a denial of service. The highest threat from this vulnerability is to system availability.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-17386

    Last Modified: 8 May 2025

    Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With cookie of an authenticated user, attackers can temper with the URL parameter and access arbitrary file on system.

    Published: 25 Aug 2020
    7.5
    High

    CVE-2020-17385

    Last Modified: 8 May 2025

    Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.

    Published: 25 Aug 2020
    7.2
    High

    CVE-2020-17384

    Last Modified: 8 May 2025

    Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.

    Published: 25 Aug 2020
    5.4
    Medium

    CVE-2020-5620

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.

    Published: 25 Aug 2020
    5.4
    Medium

    CVE-2020-5619

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via unspecified vectors.

    Published: 25 Aug 2020
    6.1
    Medium

    CVE-2020-5541

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.

    Published: 25 Aug 2020
    6.1
    Medium

    CVE-2020-5540

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to inject arbitrary script or HTML via a specially crafted URL.

    Published: 25 Aug 2020
    8.1
    High

    CVE-2020-24616

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-15670

    Last Modified: 19 Aug 2026

    Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-15664

    Last Modified: 19 Aug 2026

    By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, Firefox ESR < 78.2, and Firefox for Android < 80.

    Published: 25 Aug 2020
    7.8
    High

    CVE-2020-14361

    Last Modified: 29 Aug 2025

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-15669

    Last Modified: 21 Nov 2024

    When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6558

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6564

    Last Modified: 21 Nov 2024

    Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6566

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 25 Aug 2020
    4.3
    Medium

    CVE-2020-6570

    Last Modified: 21 Nov 2024

    Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.

    Published: 25 Aug 2020
    7.8
    High

    CVE-2020-14345

    Last Modified: 21 Nov 2024

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Aug 2020
    7.8
    High

    CVE-2020-14346

    Last Modified: 29 Aug 2025

    A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Aug 2020
    7.8
    High

    CVE-2020-14362

    Last Modified: 29 Aug 2025

    A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-15667

    Last Modified: 21 Nov 2024

    When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

    Published: 25 Aug 2020
    —
    Unknown

    CVE-2020-24642

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 25 Aug 2020
    —
    Unknown

    CVE-2020-24643

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 25 Aug 2020
    —
    Unknown

    CVE-2020-24644

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 25 Aug 2020
    —
    Unknown

    CVE-2020-24645

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6560

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6562

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6565

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6567

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6568

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 25 Aug 2020
    4.3
    Medium

    CVE-2020-6571

    Last Modified: 21 Nov 2024

    Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 25 Aug 2020
    7.8
    High

    CVE-2020-14363

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-15663

    Last Modified: 21 Nov 2024

    If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation of an older bug and arbitrary code execution with System Privileges. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 80, Thunderbird < 78.2, Thunderbird < 68.12, Firefox ESR < 68.12, and Firefox ESR < 78.2.

    Published: 25 Aug 2020
    8.8
    High

    CVE-2020-6559

    Last Modified: 21 Nov 2024

    Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6561

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 25 Aug 2020
    6.5
    Medium

    CVE-2020-6563

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.

    Published: 25 Aug 2020
    6.3
    Medium

    CVE-2020-6569

    Last Modified: 21 Nov 2024

    Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 25 Aug 2020
    6.8
    Medium

    CVE-2020-24613

    Last Modified: 21 Nov 2024

    wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect implementation of the TLS 1.3 client state machine. This allows attackers in a privileged network position to completely impersonate any TLS 1.3 servers, and read or modify potentially sensitive information between clients using the wolfSSL library and these TLS servers.

    Published: 24 Aug 2020
    8.8
    High

    CVE-2020-24572

    Last Modified: 21 Nov 2024

    An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and execute commands on the system (including ones for uploading of files and execution of code).

    Published: 24 Aug 2020
    8.1
    High

    CVE-2020-7377

    Last Modified: 21 Nov 2024

    The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.

    Published: 24 Aug 2020
    7.1
    High

    CVE-2020-7376

    Last Modified: 21 Nov 2024

    The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

    Published: 24 Aug 2020